User Email Visibility
Description:
Older versions of Atlassian Confluence provide 3 options to configure email address privacy: Public, Masked and Only visible to site administrators. It is recommended to set the email address visibility to Only visible to site administrators to maintain email privacy of existing users.
Testing:
There is no specific testing procedure for this misconfiguration. Email addresses are visible next to the user's name on posts for example.
Remediation:
To configure the visibility policy of user emails on older versions of Atlassian Confluence:
- Navigate to your Confluence instance and sign in 
- Open your Administrator Settings by clicking on the gear icon next to your profile picture 
- In your side navigation bar, scroll down to Security and open Security Configurations 
- Click on Edit to make the fields editable 
- Select Only visible to site administrators from the User email visibility dropdown. 
- Save your changes 

Latest versions of Confluence don't allow the Administrator to enforce email visibility settings. Instead, each individual user can now do so through his/her personal Atlassian ID portal.
- Navigate to your Atlassian Account and go to your Profile and visibility: https://id.atlassian.com/manage-profile/profile-and-visibility 
- Next, scroll down to the Contact section 
- And under Who can see this? next to your email-address, select Only you and admins 
- Your changes will be saved automatically 

Potential Impact:
If user email visibility is set to Public, existing user's email addresses will be displayed publicly to anyone. This may not impose a direct security risk to an organization or company but could potentially help in further exploitation and in information gathering.
References:
Last updated
Was this helpful?
