Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-12404

Restrict the transmission of Confluence version details

XMLWordPrintable

    • We collect Confluence feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

      I noticed that on several installs, Confluence by default displays its full version number and sometimes build number to the world.

      It is a commonly accepted web security practice to withhold all product details, including version information, except to users on a "need to know" basis. Otherwise, you provide hackers key information they can use to attack your systems.

      It is also a commonly accepted web security practice for applications to be secure in their default configuration.

      Please have Confluence's default configuration respect best practices and withhold all product details except to product administrators or those authorized by the administrators.

            Unassigned Unassigned
            dc8cdf9b05da Aren Cambre
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: