-
Type:
Suggestion
-
Resolution: Won't Fix
-
None
-
Component/s: None
-
Environment:All versions of Confluence from what I understand
Confluence does not prevent someone from making a script that tries every possible password combination for a Confluence account. There should be an option to set a max attempts and then lock out the user from the system. This is obviously a security problem as Confluence within most companies uses LDAP to authenticate and if user's LDAP's are breached then many other applications are breached.
- is duplicated by
-
CONFSERVER-18169 Account lockout feature
- Closed