Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Enabling Smart Commits - Security Note Clarification

Leon Degiorgio
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
March 8, 2022

Hi all,

I would like to get some clarifications on the small security note mentioned in the "Enable Smart Commits" documentation.

A small security note

Elevated access rights in Jira products can result from the way that Git (and Mercurial) allow commits to be attributed to a user other than the user pushing a change to the repository.

If this seems like a risk for your situation, then you should consider disabling Smart Commits in your Jira site.

 

Can someone please elaborate a bit further on what might be impacted or a particular scenario where or how this might occur?

1 answer

0 votes
Fabrizio Catalucci
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
January 15, 2025

I think the explanation could be like this.

It is easy to "spoof" the email address of the author of a Git commit: a malicious user could get his commits to be attributed to another user in Jira, in order to trigger workflow transitions with elevated privileges.

Suggest an answer

Log in or Sign up to answer