User may view some information in credential-store of other users

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

    • Type: Bug
    • Resolution: Fixed
    • Priority: Major
    • Environment:

      As a standard user, it is possible to directly access other user's credential-store when this is not a menu option provided to them.

      By manually entering another user's name into the location field of the browser, an unprivileged user can view the list of credentials in another users' credential-store. It doesn't appear to be possible to view the stored password, but all credentials information for a given user should be restricted from access by other users.

            Assignee:
            Stephen Connolly
            Reporter:
            Josh Cook
            Archiver:
            Jenkins Service Account

              Created:
              Updated:
              Resolved:
              Archived: