Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

During the synchronization process, unauthorized information (tag information) was also synced to Jira. #301

Open
echo54yu opened this issue Sep 13, 2024 · 4 comments
Labels
as intended question Further information is requested

Comments

@echo54yu
Copy link

echo54yu commented Sep 13, 2024

We are using version 2.0.6 and have set up a synchronization account that is only authorized to sync certain assets to Jira, not other tag information. However, the account has accessed all tag information.
This issue has arisen recently, although our configuration files have not been updated in months. Could there be any underlying design changes in Tenable?
Information visible to the sync account_tag 2
Jira synced to many tags without authorization

@echo54yu
Copy link
Author

https://docs.tenable.com/release-notes/Content/vulnerability-management/2024.htm
I have seen information posted here within the last seven days. Will this affect the synchronization of findings information?

@SteveMcGrath
Copy link
Collaborator

The integration will pull all tags for the filtered assets as provided by the API. While the assets are filtered to specific tags, all tags associated to those assets will be returned. The integration simply translates the related tags into Jira.

@SteveMcGrath SteveMcGrath added question Further information is requested as intended labels Sep 16, 2024
@echo54yu
Copy link
Author

The integration will pull all tags for the filtered assets as provided by the API. While the assets are filtered to specific tags, all tags associated to those assets will be returned. The integration simply translates the related tags into Jira.

So, all the vulnerabilities synced to JIRA will get all the tag information, right? Why were other tags not synced before this month?

@SteveMcGrath
Copy link
Collaborator

I can't answer that, as the integration is blindly reconstructing the tags from the asset export API. There haven't been any changes to tag behavior since shortly after the rewrite.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
as intended question Further information is requested
Projects
None yet
Development

No branches or pull requests

2 participants