Security Issue: Access to wiki pages, although anonymous access is disabled

XMLWordPrintable

    • Type: Bug
    • Resolution: Duplicate
    • Priority: Medium
    • None
    • Affects Version/s: 2.5.4
    • Component/s: None
    • Environment:

      While testing the Confluence Wiki, we disabled the anonymous access to the Wiki.

      Nevertheless, access to several Wiki pages is still possible while not being logged in (=anonymous access).

      To reproduce the error, use the latest standalone where anonymous access is disabled by default. Then use any of the links below, e.g.

      http://<confluence based url>/dwr/index.html
      http://<confluence based url>/labels-javascript
      http://<confluence based url>/download
      http://<confluence based url>/rpc/xmlrpc
      http://<confluence based url>/rpc/soap-axis/confluenceservice-v1?wsdl
      http://<confluence based url>/setup/setupadministrator.vm

              Assignee:
              Unassigned
              Reporter:
              Vincent Chang
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: