Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-31014

User lister action has no cross-site request forgery (XSRF) protection

    XMLWordPrintable

Details

    Description

      Confluence allows an administrator to configure the groups which will not be allowed for member listing by the userlister macro. The doconfigure action that implements this functionality is vulnerable to cross-site request forgery (XSRF). An attacker who exploited this vulnerability could cause the group black-list to be cleared.

      A GET request to the following location (as an elevated administrator) is enough to invoke this action:

      /admin/userlister/doconfigure.action?blackListEntries=confluence-administrators&save=Save

      If the blackListEntries parameter value is removed, the user lister group black list is removed completely.

      Attachments

        Issue Links

          Activity

            People

              psaw PatrickA
              a136c65a63df Phillip Langlois
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: