-
Bug
-
Resolution: Fixed
-
High
-
2.4.3, 2.9
-
None
If the id of a page is known by a user, that user can view the content of the page without having permissions to the space it is in. They need only construct the right URL.
EG:
Two spaces A and B
Page with id 1 is in Space A
User cannot see Space A
User can see Space B
The following URL will allow the user to copy the page to space B and view its content.
http://confluence.example.com/pages/copypage.action?spaceKey=B&idOfPageToCopy=1
- relates to
-
CONFSERVER-12860 Hidden pages' content can be viewed without permission using diffpages.action
-
- Closed
-