Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-23633

Actions doeditpage,domovepage,docreatepage do not require XSRF token

    XMLWordPrintable

Details

    Description

      When checking the application for security leaks, I found that the actions doeditpage, domovepage and docreatepage explicitly set the requireSecurityToken=false in the xwork.xml. This could be a possible leak in an attack scenario. Is there a reason, why these actions should not require the security token, perhaps incompatibilities,...?

      Attachments

        Issue Links

          Activity

            People

              jxie Chii
              da52405f9e46 Michael Ammann
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: