Atlassian Jira Service Desk Open Signups
Last updated
Last updated
Atlassian Jira Service Desk may have misconfigured permissions and allow anyone to signup and get access to private or internal company support tickets via the ServiceDesk signup app route.
Navigate to the following app route and check if signups are enabled:
Make sure to disable signups for Service Desk. One way to do so is:
Visit your Jira Service Desk Configuration (https://{yourAtlassian}.atlassian.net/jira/settings/products/servicedesk/customer-access
)
Next, open up Customer access from the side-navigation bar
Make the appropriate changes and remove Portal access for non-authorized users
Save your settings
To further secure your company from unauthorized access to your Atlassian products, you are recommended to enforce an email domain whitelist:
To do so:
Visit your Atlassian Administrator panel
Open User access settings from the side navigation bar
Next, remove all access from Any domain if you haven't already
Verify and add your own domain to only allow users with your whitelisted domain to get access
In the event that everyone can signup for an Atlassian Service Desk account, unauthorized users would be able to view and read sensitive data such as support tickets, internal-only company data and in severe cases also personal identifiable information of employees and customers. In addition to that and depending how dependent an organization or company is on Atlassian's Service Desk: It is also possible to request internal company support for for example a new access badge, requesting employment contract changes (salaries), requesting access to third-party accounts (social media accounts) and so on.