We are trying to enable the API access in confluence. Is it safe to enable API access and is there any way that way can restrict API access to known peers?
My opinion: Is not that safe, but you can enable it.
You see, anyone who knows JSON or REST calls will be able to retrieve content or post it. The only way to restrict the API is disabling the anonymous access in Confluence, then only your Confluence users will be able to use rest calls.
Two vulnerabilities have been published for Confluence Server and Data Center recently: March 20, 2019 CVE-2019-3395 / CVE-2019-3396 April 17, 2019 CVE-2019-3398 The goal of this article is...
Connect with like-minded Atlassian users at free events near you!Find an event
Connect with like-minded Atlassian users at free events near you!
Unfortunately there are no Community Events near you at the moment.Host an event
You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events