JIRA Mobile Plugin not secured?

  • joawal
Posted: Wed, 04/09/2014 - 09:41

We have found a serious security issue. If a user access an issue with secured fields from a mobile device the hidden fields and corresponding data are displayed. You have to click on the "More" link to see the custom fields. We are using JIRA 6.1.7.