I found documentation for Confluence Cloud that states one must be a Space Admin to move pages from that space to another space.
https://support.atlassian.com/confluence-cloud/docs/move-copy-and-hide-pages/
For Confluence Data Center 8.5.4. I found this page states that you need only the Delete permission within the space, not Space Admin
https://confluence.atlassian.com/conf85/move-and-reorder-pages-1283359685.html
Does anybody have insights or links to documents/announcements that would explain why Space Admin permissions are required in Cloud, when they are not required in DC?
Hi @Trudy P Claspill
We want to explain changes to cross-space page moves that resulted from patching a recently discovered vulnerability. The changes desupport an estimated 10-15% of cross-space page moves. What was the vulnerability? Summary: Moving a subtree (page+child pages) across spaces could allow for a user to inappropriately access and modify previously restricted child pages. Given a user with the following permissions: In the Source Space User is NOT a space admin User has delete page permission User has create page permission User has edit restrictions on the page In the Target Space User is a space admin the user can move a page and all child pages to a space where they are a space admin. In the Manage Pages>Restricted admin screen, the user can then access any previously restricted child pages. How did we patch it? Only space admins of the source space can move a page out of the space. This patches the vulnerability as the space admin of the source is already allowed to access those restricted pages via the Manage Pages>Restricted admin screen.
We want to explain changes to cross-space page moves that resulted from patching a recently discovered vulnerability. The changes desupport an estimated 10-15% of cross-space page moves.
Summary: Moving a subtree (page+child pages) across spaces could allow for a user to inappropriately access and modify previously restricted child pages.
Given a user with the following permissions:
Source
User is NOT a space admin
space admin
User has delete page permission
delete page
User has create page permission
create page
User has edit restrictions on the page
edit
In the Target Space
Target
User is a space admin
the user can move a page and all child pages to a space where they are a space admin. In the Manage Pages>Restricted admin screen, the user can then access any previously restricted child pages.
Only space admins of the source space can move a page out of the space. This patches the vulnerability as the space admin of the source is already allowed to access those restricted pages via the Manage Pages>Restricted admin screen.
It looks like you're new here. Sign in or register to get started.