HIGH 7.5 Maven
com.xwiki.confluencepro:application-confluence-migrator-pro-ui's application homepage is public
GHSA-3w9f-2pph-j5vc · CVE-2025-27604
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
The homepage of the application is public which enables a guest to download the package which might contain sensitive information.
Patches
1.11.7
Workarounds
The access to the page can be manually restricted to a specific set of users or groups.
References
- WEB https://github.com/xwikisas/application-confluence-migrator-pro/security/advisories/GHSA-3w9f-2pph-j5vc
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-27604
- WEB https://github.com/xwikisas/application-confluence-migrator-pro/commit/6ced42b1f341fd0ce6734fc58c7d694da5f365fb
- PACKAGE https://github.com/xwikisas/application-confluence-migrator-pro
Ready to move
Start Securing
Free, no credit card | First findings in minutes