Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-31187

Default application configuration files are available for download

    XMLWordPrintable

Details

    Description

      Summary of The Bug

      By browsing to the following URL path user would be able to download any files under <JIRA_Install_Dir>/atlassian-jira/WEB-INF/...

      <Server Base URL>/s/1519/3/1.0/_/WEB-INF/...

      The above URL will be accessible by any users including anonymous even to an instance that does not allow anonymous access

      Notes

      This issue is not reproducible in IE9 (IE8 leads to the same issue)

      Attachments

        1. a-regular-404.png
          a-regular-404.png
          10 kB
        2. web-inf-404.png
          web-inf-404.png
          12 kB

        Issue Links

          Activity

            People

              edalgliesh Eric Dalgliesh
              scahyadiputra Septa Cahyadiputra (Inactive)
              Votes:
              1 Vote for this issue
              Watchers:
              18 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: