•  
      request #29224 Site Administrator profile is not private
    Infos
    #29224
    Satyam Patel (satyam_patel)
    2022-10-17 14:49
    2022-10-17 01:41
    30799
    Details
    Site Administrator profile is not private

    The site administrator profile must be private if an attacker gets access by brute-forcing attacker can delete/copy/sell all the private projects code. 

    2493-image.png

    Empty
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Empty
    Declined
    2022-10-17
    Attachments
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2022-10-17 14:49

    Thanks for your kind response. I was thinking to use tuleap for my project but, as per your statement exposing all user information is this application's behaviour it's a violation of CIA triad properties.

    Note that you can make instance private if you want. See the documentation: https://docs.tuleap.org/administration-guide/users-management/security/site-access.html#site-configuration

    I was casually browsing the project features, it was not a security test.

    The real name you had set does not tell the same story but okay.


    User avatar

    Dear @thomas.gerbet@enalean.com,

    Thanks for your kind response. I was thinking to use tuleap for my project but, as per your statement exposing all user information is this application's behaviour it's a violation of CIA triad properties. I will not use this product in my project.

    Anyway, if your production is exposing users' confidential information, please consider proper authorisation to comply with CIA triad.
    I was casually browsing the project features, it was not a security test.

    Thanks and regards!

    Satyam Patel Security Researcher@synackz

    User avatar
    Thomas Gerbet (tgerbet)2022-10-17 09:26

    Hello,

    Same as request #29223 this is an expected behavior.

    Also, please do not search for security issues on a production instance you do not want. Our guidelines on how to report security issues are available here: https://www.tuleap.org/security


    • Status changed from New to Declined
    • Close date set to 2022-10-17