We used JIRA Cloud and today I randomly received this email:
Several questions:
* The message subject looks seriously weird, is that correct?
* I didn't know that there was a public "Contact Administrators" page with JIRA Cloud? Where is it? I did some googling but could only find references to JIRA Server.
* How can I turn this off to public access? There is nobody called test@test.com in my organisation
Hi all,
> The message subject looks seriously weird, is that correct?
It looks like someone is testing for a security vulnerability which we disclosed on July 10, 2019: https://confluence.atlassian.com/jira/jira-security-advisory-2019-07-10-973486595.html. Please note that Jira Cloud customers are not affected by this issue.
> I didn't know that there was a public "Contact Administrators" page with JIRA Cloud? Where is it? I did some googling but could only find references to JIRA Server.
> How can I turn this off to public access? There is nobody called test@test.com in my organisation
As others here have noted, there is a "Contact Administrators Form" setting which you can turn off.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I just turned off the Contact Administrators form in the general settings as suggested by Jimmy.
But I'm still not clear what this Contact Administrators form looks like or how a user would see it
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Chris,
I'll be honest I didn't know about this one myself. However I found it!
If you click on the admin cog and got to the "Settings" menu.
You will find it under "General configuration". You will need to click the "Edit Settings" button in the top right corner in order to change the setting, and you will see it just before the rich text editor box.
I hope that helps!
-Jimmy
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Good spot with the configuration.
But where is this "Contact Administrators" page, how would somebody find it? What is its URL?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hey Chris,
I'm not 100% sure, but looking at the Confluence documentation it indicated users would see that link if they encountered an error. So I imagine if the user failed to login, that link might be presented as a part of the error message?
-Jimmy
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi,
The related resource is found at https://<jira>/secure/ContactAdministrators!default.jspa .
There is a "Contact Administrators Form" setting which you can turn off & doing so will disable the functionality.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks for the post @Chris Jones and thanks for the answers too @David Black all. This helped me figure this out as well.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.