laptop and a wrench

Bug

The ArcGIS Portal Directory REST API reveals user information and allows for user enumeration via the user resource endpoint, even when accessed anonymously.

Portal for ArcGIS
Bug-ID-Nummer BUG-000171101
EingereichtSeptember 30, 2024
Zuletzt geändertOctober 3, 2024
Gilt fürPortal for ArcGIS
Gefunden in Version11.1
BetriebssystemWindows Server
Betriebssystemversion2022
StatusAs Designed

Zusätzliche Informationen

When the portal is configured to share content with the public, it is necessary to wait for anonymous users to decide whether they trust the content. One aspect of trust is knowing who shared that content. This means that it is necessary for anonymous users to know the names of users who are creating content, adding comments, etc. This is a security feature that is common in most products that share content with the public.

Schritte zur Reproduzierung

Bug-ID: BUG-000171101

Software:

  • Portal for ArcGIS

Benachrichtigung erhalten, wenn sich der Status eines Bugs ändert

Esri Support App herunterladen

Weitere Informationen zu diesem Thema erkunden

Unterstützung durch ArcGIS-Experten anfordern

An den technischen Support wenden

Esri Support App herunterladen

Zu Download-Optionen wechseln