Use Cases

1 JIRA is showing Popular Filters (shared with all users) to user which are not logged in!


Does your JIRA also show all Filters which are "shared with all users" to really everyone in the world?

Just try the following:

  1. Make sure that you are not logged in
  2. Type in the following URL in your browser:
    https://your-jira-domain.com/secure/ManageFilters.jspa
  3. Do you also see something like this? 

As you can see - without logging in you can get information about saved filters and names + mail adress from the filter owner.

Protect this data with our Prevent Anonymous Access Plugin!

 

2 JIRA is showing Popular Dashboards (shared with all users) to user which are not logged in!

Does your JIRA also show all Dashboards which are "shared with all users" to really everyone in the world?

Just try the following:

  1. Make sure that you are not logged in
  2. Type in the following URL in your browser:
    https://your-jira-domain.com/secure/ConfigurePortalPages!default.jspa 
  3. Do you also see something like this? 

 

 

As you can see - without logging in you can get information about saved Dashboards and names from the dashboard owner.

Protect this data with our Prevent Anonymous Access Plugin!

 

3 JIRA is interacting to user which are not logged in!

Also you are not logged in JIRA is interacting with so called anonymous user. Here you find some examples:

Also you won't get any issue data, the JIRA system is responding and interacting. 

If you think this is not an acceptable behaviour.

Protect this data with our Prevent Anonymous Access Plugin!