The renderContent method can be used by anonymous users, leaking information, and allowing macro execution.

      Should the entire JSON-RPC be inaccessible to anonymous users if anonymous users can't use confluence?

            [CONFSERVER-32955] JSON-RPC API allows anonymous content rendering

              vvo Vu Truong Vo (Inactive)
              djohnson@atlassian.com Dougall Johnson
              Affected customers:
              1 This affects my team
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: