Details
-
Bug
-
Status: Closed (View Workflow)
-
Critical
-
Resolution: Done
-
prod/bigpicture/jiracloud/2021/01/08/12_30, prod/biggantt/jiracloud/2021/01/08/12_30, prod/biggantt/jiraserver/2021/02/09/8.0.20, prod/bigpicture/jiraserver/2021/02/09/8.0.20
-
prod/bigpicture/jiracloud/2021/03/19/15_12, prod/biggantt/jiracloud/2021/03/19/15_12, prod/biggantt/jiraserver/2021/03/22/8.0.22, prod/bigpicture/jiraserver/2021/03/22/8.0.22, prod/biggantt/jiracloud/2021/06/18/22/20, prod/bigpicture/jiracloud/2021/06/18/22/20, prod/biggantt/jiraserver/2021/07/13/18/00/8.1.0, prod/bigpicture/jiraserver/2021/07/13/18/00/8.1.0
-
None
-
No
-
Tree
-
BigPicture, BigGantt
-
JIRA server, JIRA cloud
-
5
-
1
-
-
2 hours, 13 minutes, 59 seconds -
1 day, 19 hours, 47 seconds -
1 week, 45 minutes, 24 seconds -
0 -
1 minute, 20 seconds -
2 days, 5 hours, 10 minutes, 45 seconds -
2 weeks, 7 hours, 26 minutes, 17 seconds -
Description
Prerequisites:
N/A
Reproduction steps:
Log in as Box Viewer and delete tasks (eg. basic task).
Actual result:
User can delete any task by using rest api due to insufficient security in backend side.
Expected result:
User cannot delete basic tasks or other tasks from different extplatforms (eg Jira or Trello) from the application level.
Workaround:
N/A