-
Bug
-
Resolution: Fixed
-
Medium
-
2.6.0
-
None
This gives a potential attacker lots of information about available AJAX request handlers in Confluence.
- is duplicated by
-
CONFSERVER-9727 Security Issue: Access to wiki pages, although anonymous access is disabled
-
- Closed
-
If you need to manually fix this problem on your instance you should edit the <confluence install>/confluence/WEB-INF/web.xml and locate the following lines -
Change the param-value to false.