Details
-
Bug
-
Resolution: Fixed
-
Critical
-
15.10.13
-
Unknown
-
N/A
-
N/A
-
Description
It's possible as guest user to get access to Authentication/Administration and Authentication/Configuration, allowing anyone to see information about the authentication mechanism put in place for the wiki, which might be sensitive information.
Attachments
Issue Links
- is duplicated by
-
XWIKI-22604 Anyone can change the authenticator of a wiki
-
- Closed
-