Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-30887

doremovespacemail action can be called by non-admins

    XMLWordPrintable

Details

    Description

      The doremovespacemail action is provided by the confluence-mail-archiving plugin, and allows all of the archived mail associated with a space to be removed. This action can be called by any authenticated user, which appears to be an oversight in access control, given that similar methods (such as doremovemail) firstly check that the caller has REMOVE_MAIL_PERMISSION permission.

      This could allow a malicious Confluence user who only has view access to a particular space to remove all of the archived mail from that space.

      Attachments

        Issue Links

          Activity

            People

              psemeniuk Petro Semeniuk (Inactive)
              4d658525b00b Richard Turnbull
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: