Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Atlassian app redirect using unencrypted user email is insecure

cybertrapped July 9, 2024

When I click the Trello app tile from Atlassian's app switcher menu, the URL syntax appears as

https://trello.com/appSwitcherLogin?login_hint=myEmail@example.com

The screenshot below illustrates the URL I see when I hover my mouse over the Trello app tile that is presented to me after I click the Apps menu

Atlassian Home - User Interface - App Switcher Menu - app URL includes user account email in clear text.png

I am not a cybersecurity expert, but I think using unencrypted identifiable account information through the redirect URL is insecure.

I'd like to know what other users think. If you are reading this, please share your thoughts.

0 comments

Comment

Log in or Sign up to comment
TAGS
AUG Leaders

Atlassian Community Events