Hi all,
I would like to get some clarifications on the small security note mentioned in the "Enable Smart Commits" documentation.
Elevated access rights in Jira products can result from the way that Git (and Mercurial) allow commits to be attributed to a user other than the user pushing a change to the repository.
If this seems like a risk for your situation, then you should consider disabling Smart Commits in your Jira site.
Can someone please elaborate a bit further on what might be impacted or a particular scenario where or how this might occur?
I think the explanation could be like this.
It is easy to "spoof" the email address of the author of a Git commit: a malicious user could get his commits to be attributed to another user in Jira, in order to trigger workflow transitions with elevated privileges.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.