Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-30886

User invite functionality available to non-admins

    XMLWordPrintable

Details

    Description

      The REST API which manages user invites ensures that only adminstrators can generate a new invite token. However, no similar access controls are present on the methods which are used to invite new users, or to revert to the previous security token – these can be successfully called by any authenticated user.

      This could allow malicious Confluence users to control the security token which is in use (for example, if an administrator discovered that a token had been compromised and generated a new one, the attacker could use the method described below to revert to the previous one) or to invite new users to sign up to Confluence. The malicious user could also obtain the current token by requesting that an invite be sent to themselves.

      Attachments

        Issue Links

          Activity

            People

              igerges Issac Gerges (Inactive)
              4d658525b00b Richard Turnbull
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: