Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-24089

Error message and/or navigation menu reveal which pages exist for users without view right

    XMLWordPrintable

Details

    • Bug
    • Resolution: Unresolved
    • Major
    • None
    • 17.10.2
    • Rendering - XWiki
    • Unknown

    Description

      When user tries to see a page where he/she has no view right the navigation menu on the left does not show the current page. But if the page does not exist at all the navigation menu inserts a "placeholder" with the page name. 

      Also the error message when trying to view a page where the user has no view right is "You are not allowed to view this page or perform this action." whereas on a page that doesn't exist it's "The requested page could not be found." and displays a list of alternative existing pages.

      This behavior allows the user to probe which pages exist on the wiki even though he/she has no view right on them. This could leak sensitive information.

      Attachments

        Activity

          People

            Unassigned Unassigned
            tjhvx Timo Hyrskylahti
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated: