Review GET methods in Confluence to ensure web spiders cannot execute dangerous actions (like removeattachment)

XMLWordPrintable

    • 3
    • Severity 2 - Major
    • 0

      At present, if a Confluence space admin allows Anonymous to remove attachments, web spiders can crawl and execute the removeattachment action.

            Assignee:
            Unassigned
            Reporter:
            DonnaA
            Votes:
            4 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated: