Risk Rating - High CVSS v3.1 Score - 8.6 References: https://owasp.org/API-Security/editions/2019/en/0xa3-excessive-data-exposure
Description: Excessive Data Exposure occurs when an API sends back a full data object and exposes more information or data than necessary than what the client legitimately needs, relying on the client to do the filtering. During routine browsing of the application it was noted that the application made calls to the endpoint at **/AbpUserConfiguration/GetAll **which returned a large JSON array of configuration information. The application sends the request as a default part of its initialization process, requiring no interaction from the user, and the timestamp seen in the request at parameter d was found to be optional. The tester identified that these calls could be made prior to authentication and still receive a response:
Upon further investigation the tester noted that sensitive information related to other services that the application used were contained within the JSON response, namely usernames and passwords for an internal data collection service.
1 Answer(s)
-
0
Hi @LAD666
If such sensitive information needs to be stored in application settings, it is strongly recommended that these values be encrypted to ensure their security. Furthermore, if the related settings do not need to be modified at runtime, it is advisable not to store them in the settings at all. However, if storing them in settings is necessary, the sensitive values must be encrypted as described below.
In addition, marking these values with the
DisableAuditingattribute will prevent them from being included in audit logs. However, this alone does not prevent such values from being exposed to the client, for example via theAbpUserConfigurationservice’sGetAllresponse.Therefore, for settings that should not be visible on the client side, you must properly configure the
ClientVisibilityProviderand set the appropriate setting scope. This ensures that sensitive settings remain server-side only and are not exposed to the client.Related Document
Example:
await SettingManager.ChangeSettingForApplicationAsync(DataCollector.Sftp.Password, SimpleStringCipher.Instance.Encrypt(settings.SftpPassword));Also example when defining the setting:
new SettingDefinition(DataCollector.Sftp.Password, GetFromAppSettings(DataCollector.Sftp.Password, ""), clientVisibilityProvider: new HiddenSettingClientVisibilityProvider()),Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image)

