Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-18633

/me/my-views/editDescription may be used by any user to set global description

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Minor Minor
    • core
    • Windows7 using the integrated webserver using ActiveDirectory authentication and matrix based security.

      I have a user that has only the single right "Job: read", but is still allowed to change the description of the server (main heading) for everyone.

      Could be reproduced:

      This could also be tested by directly opening the URL:
      https://SERVERNAME/me/my-views/editDescription

            jglick Jesse Glick
            dominik_ Dominik Schwald
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: