Skip to main content

Performance Issue: Confluence “Download All” Attachments Disabled

Last Updated:
2019-04-26 19:38:17
Event:
2019-04-18 20:09:00
Status:
Closed
Brief Description:
On advisement of the vendor and the IT Security Office, the option to download all attachments associated with a Confluence space with a single click is being disabled. Individual attachment downloads will continue to work.
User Impact:
Confluence users who want to download attachments for a given space will need to do so individually.
Workaround:
There is no workaround for this issue
Current Status:
The option to download all attachments associated with a Confluence space with a single click is being disabled.
Services Affected:
Wikis
Subsites Affected:
Cornell Secure File Transfer
Full Description:
On advisement of the vendor and the IT Security Office, the option to download all attachments associated with a Confluence space with a single click is being disabled. Individual attachment downloads will continue to work. The vendor has identified the “Download All” attachments option as providing a potential security vulnerability. The problem does not exist in the latest version of Confluence, so when the project underway to update Cornell Confluence concludes, this feature will be restored.

Note: The option to download all attachments will still be visible after the change, but clicking it will produce an error, “The requested resource is not available.”



Timeline of Changes

Description Current Status Date Time
On advisement of the vendor and the IT Security Office, the option to download all attachments associated with a Confluence space with a single click is being disabled. Individual attachment downloads will continue to work. The vendor has identified the “Download All” attachments option as providing a potential security vulnerability. The problem does not exist in the latest version of Confluence, so when the project underway to update Cornell Confluence concludes, this feature will be restored. Note: The option to download all attachments will still be visible after the change, but clicking it will produce an error, “The requested resource is not available.” The option to download all attachments associated with a Confluence space with a single click is being disabled. 2019-04-18 20:11:55