•  
      request #29223 Without authentication API exposing all user's(including admin) profile details without authentication
    Infos
    #29223
    Satyam Patel (satyam_patel)
    2022-10-17 09:25
    2022-10-17 01:28
    30798
    Details
    Without authentication API exposing all user's(including admin) profile details without authentication

     

    URL: https://tuleap.net/api/users/101

    Without authentication, attackers can access all users' information. And can brute force the to take over the admin account.

    POC: 2492-image.png

    Authentication & LDAP
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Empty
    Declined
    2022-10-17
    Attachments
    References
    Referencing request #29223

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2022-10-17 09:25

    Hello,

    This is an expected behavior of the application.

    Also, please do not search for security issues on a production instance you do not want. Our guidelines on how to report security issues are available here: https://www.tuleap.org/security


    • Status changed from New to Declined
    • CC list cleared values: Manuel Vacelet (Admin) (admin_manuel), Site Administrator (admin), Laurent Charles (Admin) (admin_laurent), Nicolas Terray (Admin) (admin_nicolas)
    • Close date set to 2022-10-17