Absence of Anti-CSRF Tokens

manish jangir March 13, 2024

Currently, our Confluence version is 8.5.3. During the assessment, it was identified that the anti-CSRF Token was missing. This token is a security measure used to prevent attackers from carrying out CSRF attacks.

1. Please guide us to enable the respective token.

2. If the above token is to be replaced with another token then suggest to us, which token is that.

3. If the above token is not needed then provide us with the supporting document.

1 answer

1 accepted

1 vote
Answer accepted
Marc - Devoteam
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
March 14, 2024

Hi @manish jangir 

XSRF (Cross Site Request Forgery) is by default enabled in Confluence.

So it has to been disabled by someone.

See the article here on the description to enable it again.

configuring-xsrf-protection 

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
VERSION
8.5.3
TAGS
AUG Leaders

Atlassian Community Events