Closed
Description
This is more about include file request than an issue. I could do the push request but not sure if you'd approve.
Here https://confluence.atlassian.com/doc/using-apache-to-limit-access-to-the-confluence-administration-interface-216433019.html we can find administration actions paths that should be protected.
IMO you could add the list below under /Discovery/Web-Content/ since an attacker could find them through any discovery tool.
/confluence/admin
/confluence/plugins/servlet/oauth/consumers/list
/confluence/plugins/servlet/oauth/view-consumer-info
/confluence/plugins/servlet/oauth/service-providers/list
/confluence/plugins/servlet/oauth/service-providers/add
/confluence/plugins/servlet/oauth/consumers/add
/confluence/plugins/servlet/oauth/consumers/add-manually
/confluence/plugins/servlet/oauth/update-consumer-info
/confluence/pages/templates/listpagetemplates.action
/confluence/pages/templates/createpagetemplate.action
/confluence/spaces/spacepermissions.action
/confluence/pages/listpermissionpages.action
/confluence/spaces/removespace.action
/confluence/spaces/importmbox.action
/confluence/spaces/viewmailaccounts.action
/confluence/spaces/addmailaccount.action?
/confluence/spaces/importpages.action
/confluence/spaces/flyingpdf/flyingpdf.action
/confluence/spaces/exportspacehtml.action
/confluence/spaces/exportspacexml.action
/confluence/plugins/servlet/embedded-crowd
/confluence/plugins/servlet/upm
Activity
g0tmi1k commentedon Jun 13, 2018
Feel free to open up a PR!
Close danielmiessler#195 - Confluence administration