com.xwiki.confluencepro:application-confluence-migrator-pro-ui's application homepage is public
High severity
GitHub Reviewed
Published
Mar 7, 2025
in
xwikisas/application-confluence-migrator-pro
•
Updated Mar 7, 2025
Package
Affected versions
<= 1.11.6
Patched versions
1.11.7
Description
Published to the GitHub Advisory Database
Mar 7, 2025
Reviewed
Mar 7, 2025
Published by the National Vulnerability Database
Mar 7, 2025
Last updated
Mar 7, 2025
Impact
The homepage of the application is public which enables a guest to download the package which might contain sensitive information.
Patches
1.11.7
Workarounds
The access to the page can be manually restricted to a specific set of users or groups.
References