laptop and a wrench

Bug

The ArcGIS Portal Directory REST API reveals user information and allows for user enumeration via the user resource endpoint, even when accessed anonymously.

Portal for ArcGIS
Bug ID Number BUG-000171101
SubmittedSeptember 30, 2024
Last ModifiedOctober 3, 2024
Applies toPortal for ArcGIS
Version found11.1
Operating SystemWindows Server
Operating System Version2022
StatusAs Designed

Additional Information

When the portal is configured to share content with the public, it is necessary to wait for anonymous users to decide whether they trust the content. One aspect of trust is knowing who shared that content. This means that it is necessary for anonymous users to know the names of users who are creating content, adding comments, etc. This is a security feature that is common in most products that share content with the public.

Steps to Reproduce

Bug ID: BUG-000171101

Software:

  • Portal for ArcGIS

Get notified when the status of a bug changes

Download the Esri Support App

Discover more on this topic

Get help from ArcGIS experts

Contact technical support

Download the Esri Support App

Go to download options