Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-27693

Default application configuration files are available for download

    XMLWordPrintable

Details

    Description

      NOTE: This bug report is for Confluence Server. Using Confluence Cloud? See the corresponding bug report.

      Summary of The Bug

      By browsing to the following URL path user would be able to download any files under <Conf_Install_Dir>/confluence/WEB-INF/...

      <Server Base URL>/s/1519/3/1.0/_/WEB-INF/...

      The above URL will be accessible by any users including anonymous even to an instance that does not allow anonymous access

      Notes

      This issue is not reproducible in IE9 (IE8 leads to the same issue)

      Attachments

        Issue Links

          Activity

            People

              igerges Issac Gerges (Inactive)
              28a2c00cddfa Vincent Kopa (Ovyka)
              Votes:
              3 Vote for this issue
              Watchers:
              17 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: