Uploaded image for project: 'Confluence Server and Data Center'
  1. Confluence Server and Data Center
  2. CONFSERVER-27693

Default application configuration files are available for download

    XMLWordPrintable

    Details

      Description

      NOTE: This bug report is for Confluence Server. Using Confluence Cloud? See the corresponding bug report.

      Summary of The Bug

      By browsing to the following URL path user would be able to download any files under <Conf_Install_Dir>/confluence/WEB-INF/...

      <Server Base URL>/s/1519/3/1.0/_/WEB-INF/...

      The above URL will be accessible by any users including anonymous even to an instance that does not allow anonymous access

      Notes

      This issue is not reproducible in IE9 (IE8 leads to the same issue)

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              igerges Issac Gerges (Inactive)
              Reporter:
              28a2c00cddfa Vincent Kopa (Ovyka)
              Votes:
              3 Vote for this issue
              Watchers:
              17 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: