Ability to Toggle Version Information on Confluence Pages On/Off

XMLWordPrintable

    • 6
    • 10

      Suggestion Summary

      Confluence should provide administrators with a way to toggle displaying version related information on/off.

      Suggestion Details

      If unauthenticated, one can access Confluence's landing page and retrieve version related information from three places:

      • Login page footer.
      • Response Head AJS Tags.
      • Response Body What's New Link.

      Someone without good intentions could use this information to search for possible security vulnerabilities over the internet and hack Confluence. Therefore, if in a public facing instance, hiding these pieces of information can become a requirement for administrators.

      Workaround

      An administrator can modify Confluence core files to prevent this information from being displayed. The knowledge base below teaches how to do that:

            Assignee:
            Unassigned
            Reporter:
            Marcelo Horlle (Inactive)
            Votes:
            73 Vote for this issue
            Watchers:
            40 Start watching this issue

              Created:
              Updated: