Details
- 
    
Bug
 - 
    Resolution: Fixed
 - 
    
Blocker
 - 
    2.5 M2
 
Description
Reproduction steps:
- Start office server on the wiki
 - Insert a new comment with guest such as:
{{office reference="url:file:///etc/whois.conf"/}} 
Expected result:
- the file should not be displayed, only PR user should be able (maybe?) to access a file from the host like this
 
Obtained result:
- the file is displayed to anyone once the comment is saved
 
Attachments
Issue Links
- causes
 - 
                    
XWIKI-20324 SSRF - Retrieve sensitive data from server - Add Gadget
-         
 - Closed
 
 -         
 
- relates to
 - 
                    
XWIKI-20449 Server side request forgery (SSRF) with the Office Viewer
-         
 - Closed
 
 -