> For the complete documentation index, see [llms.txt](https://bugology.intigriti.io/misconfig-mapper-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://bugology.intigriti.io/misconfig-mapper-docs/services/atlassian-confluence/misconfigured-spaces.md).

# Misconfigured Spaces

#### Description:

Confluence Spaces are an integrated feature in Atlassian Confluence to help members organize content. Spaces often contain public data such as public roadmaps, guides, knowledge bases, etc.

But these spaces can also be used to store sensitive information that is meant to be only available to internal employees. In case your visibility settings are not configured properly, you may risk disclosing potentially sensitive information to anonymous users.

#### Testing:

Visit the following application route to check if anonymous users can view and read any information on Confluence Spaces:

```
https://<companyName>.atlassian.net/wiki/spaces
```

<figure><img src="https://867675796-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHax8VYP6nSo5n66iSR0Z%2Fuploads%2Fgit-blob-99c6db77bb0d9c8faa39910e233909ceacdeddba%2F4.png?alt=media" alt=""><figcaption></figcaption></figure>

Next, manually examine every Space for hardcoded credentials, sensitive data (such as financial information), or other information that is not meant to be public.

<figure><img src="https://867675796-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHax8VYP6nSo5n66iSR0Z%2Fuploads%2Fgit-blob-c9bae75859a9d6114a1a90c051c43e173cfe647e%2F5.png?alt=media" alt=""><figcaption></figcaption></figure>

#### Remediation:

**To disable anonymous access to a specific Confluence Space:**

1. Navigate to `/wiki/spaces` on your Confluence site to list all your Confluence Spaces
2. Select the Space you would like to change its visibility settings off

<figure><img src="https://867675796-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHax8VYP6nSo5n66iSR0Z%2Fuploads%2Fgit-blob-f79ec3ee718b97bf9e2b867a9bf3e382ce3ca0e3%2F6.png?alt=media" alt=""><figcaption></figcaption></figure>

3. Open the settings menu by clicking on **Space settings**
4. Under **Space permissions**, click on **Anonymous access**

<figure><img src="https://867675796-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHax8VYP6nSo5n66iSR0Z%2Fuploads%2Fgit-blob-b04505673ae48c9c53067d0f6d1121cb37bfbe5a%2F7.png?alt=media" alt=""><figcaption></figcaption></figure>

5. Next, make sure to uncheck all permissions.
6. Finally, click **Save** to save all your settings.

<figure><img src="https://867675796-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHax8VYP6nSo5n66iSR0Z%2Fuploads%2Fgit-blob-d854bc4aee8bdc43c8cceca1b576f02dc0ff7a86%2F8.png?alt=media" alt=""><figcaption></figcaption></figure>

Once finished, you should not be able to view the COnfluence Space as an anonymous user:

<figure><img src="https://867675796-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHax8VYP6nSo5n66iSR0Z%2Fuploads%2Fgit-blob-dbffedb001a0ce0f3f22ee9c0ce3910512d8740a%2F9.png?alt=media" alt=""><figcaption></figcaption></figure>

**To entirely disable anonymous-level access on your Confluence site:**

1. Click on the gear-icon on the top-right of your screen
2. Open the **Global permissions** tab under **Security**
3. Open the **Anonymous access** tab
4. Cross-check that **all permissions are disabled for Anonymous users**
5. Finally, save all your changes by clicking on **Save**

<figure><img src="https://867675796-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHax8VYP6nSo5n66iSR0Z%2Fuploads%2Fgit-blob-e21b2142134018109c7ac9161577428ec1440ee5%2F10.png?alt=media" alt=""><figcaption></figcaption></figure>

#### Potential Impact:

Unintentionally exposing private information (such as hard-coded secrets, internal financial data or even customer data) can introduce your company or organization to further attacks by bad actors. Generally allowing them to obtain a greater foothold in your network.

#### References:

* <https://infosecwriteups.com/hundreds-of-companies-internal-data-exposed-the-confluence-cloud-misconfiguration-63cbc143caea>
* <https://confluence.atlassian.com/doc/assign-space-permissions-139460.html>
* <https://support.atlassian.com/confluence-cloud/docs/make-a-space-public/>
