Описание
com.xwiki.confluencepro:application-confluence-migrator-pro-ui's application homepage is public
Impact
The homepage of the application is public which enables a guest to download the package which might contain sensitive information.
Patches
1.11.7
Workarounds
The access to the page can be manually restricted to a specific set of users or groups.
Пакеты
com.xwiki.confluencepro:application-confluence-migrator-pro-ui
<= 1.11.6
1.11.7
Связанные уязвимости
XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. The homepage of the application is public which enables a guest to download the package which might contain sensitive information. This vulnerability is fixed in 1.11.7.
Уязвимость инструмента для миграции данных XWiki Confluence Migrator Pro, связанная с недостаточной защитой служебных данных, позволяющая нарушителю раскрыть защищаемую информацию