Details
-
Bug
-
Resolution: Unresolved
-
Medium
-
None
-
7.20.0, 7.20.1, 8.1.0, 8.1.1, 8.5.1
-
5
-
Severity 3 - Minor
-
1
-
Description
Issue Summary
This is reproducible on Data Center: YES.
Steps to Reproduce
Steps on Bulldog:
- Sign in as a user with all of these permissions: Can Use, Personal Space, Create Space(s), Confluence Administrator (optional), System Administrator. Note that this use should not be present in the user group confluence-administrators.
- Navigate to kxu's profile: https://bulldogwiki.internal.atlassian.com/wiki/display/~kxu
- You should be able to view the page "Copy of Kalvin test page" in the activity list.
- Open this page and you should get a "Page Not Found" error.
More general steps
- As a non-admin user, create a new space.
- In the permission settings for that space, change it so that no groups have access to and no other users have any permissions.
- Sign in as a user with all of these permissions: Can Use, Personal Space, Create Space(s), Confluence Administrator (optional), System Administrator. Note that this use should not be present in the user group confluence-administrators.
- View the non-admin user's profile and spot their activity of creating the new space. Alternatively access this from the #all-updates section on the home page.
- Try to open the space (or a space within the space) from the activity feed.
Expected Results
Either the space and page should not appear on the activity feed at all, of if for some reason it is supposed to appear, opening the page should result in being able to view the page instead of a "Page Not Found" error.
Actual Results
- "Page not found" when the admin user tries to view the page.
- "Not Permitted" when the admin user tries page for space.
Workaround
N/A
Attachments
Issue Links
- follows
-
VULN-1033846 Loading...