Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-25350

'/users/userpicker.action' exposes users loginids and full names in instance with anonymous access enabled

      LDAP directory users and groups exposed via the /users/userpicker.action.

      There should be an option to restrict this to authenticated users only and perhaps this should be the default behavior.

      The second exposed function that is part of this vulnerability is /spaces/opengrouppicker.action which can be accessed by anonymous users for internal directory browsing.

            [CONFSERVER-25350] '/users/userpicker.action' exposes users loginids and full names in instance with anonymous access enabled

            No work has yet been logged on this issue.

              jxie Chii (Inactive)
              gnedel Guilherme Nedel (Inactive)
              Affected customers:
              0 This affects my team
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: