Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-14014

Word import with Office Connector can overwrite existing content without permission

      It's possible under a specific set of circumstances that a user could perform actions they may otherwise be unauthorized to perform using the document import feature of the Office Connector. The specific actions would be editing or deleting a page they don't have permission to change.

      Note that this bug doesn't expose content to unauthorized users.

        1. OfficeConnector-1.4.jar
          7.92 MB
          Andrew Lynch

          Form Name

            [CONFSERVER-14014] Word import with Office Connector can overwrite existing content without permission

            The newest version of the Office Connector plugin attached to this issue will resolve this security vulnerability.

            Andrew Lynch (Inactive) added a comment - The newest version of the Office Connector plugin attached to this issue will resolve this security vulnerability.

              rackley RyanA
              Anonymous Anonymous
              Affected customers:
              0 This affects my team
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: