Security Issue: Access to wiki pages, although anonymous access is disabled

XMLWordPrintable

    • Type: Bug
    • Resolution: Duplicate
    • Priority: Medium
    • None
    • Affects Version/s: 2.5.4
    • Component/s: None
    • Environment:

      While testing the Confluence Wiki, we disabled the anonymous access to the Wiki.

      Nevertheless, access to several Wiki pages is still possible while not being logged in (=anonymous access).

      To reproduce the error, use the latest standalone where anonymous access is disabled by default. Then use any of the links below, e.g.

      http://<confluence based url>/dwr/index.html
      http://<confluence based url>/labels-javascript
      http://<confluence based url>/download
      http://<confluence based url>/rpc/xmlrpc
      http://<confluence based url>/rpc/soap-axis/confluenceservice-v1?wsdl
      http://<confluence based url>/setup/setupadministrator.vm

            Assignee:
            Unassigned
            Reporter:
            Vincent Chang
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: