Jira Integration displays password to non-owners

d harrison

Posted on
Mar 17 2016

I have set up an integration with JIRA.

When another member on the team goes to the integration settings, he can see the password.

I would recommend that passwords (and other sensitive info) are only shown on the initial setup and then never again - or better yet, use OAuth. I had initially used my own account and my password was viewable by other members on the team who may have gone to the settings page.

I have since created a new user specifically for the raygun/JIRA integration, however I see this as a security issue.


Jamie Penney

Posted on
Mar 18 2016

Hi,

This is definitely a problem - I've put a fix in for this now and it should be released in the next hour. Thank you for bringing this to our attention! We've added a Jira OAuth option recently - is your team able to use that instead?

Cheers, Jamie


Reply