Base solution for your next web application
Open Closed

Excessive Data Exposure Through API #12457


User avatar
0
LAD666 created

Risk Rating - High CVSS v3.1 Score - 8.6 References: https://owasp.org/API-Security/editions/2019/en/0xa3-excessive-data-exposure

Description: Excessive Data Exposure occurs when an API sends back a full data object and exposes more information or data than necessary than what the client legitimately needs, relying on the client to do the filtering. During routine browsing of the application it was noted that the application made calls to the endpoint at **/AbpUserConfiguration/GetAll **which returned a large JSON array of configuration information. The application sends the request as a default part of its initialization process, requiring no interaction from the user, and the timestamp seen in the request at parameter d was found to be optional. The tester identified that these calls could be made prior to authentication and still receive a response:

Upon further investigation the tester noted that sensitive information related to other services that the application used were contained within the JSON response, namely usernames and passwords for an internal data collection service.

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

1 Answer(s)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @LAD666

    If such sensitive information needs to be stored in application settings, it is strongly recommended that these values be encrypted to ensure their security. Furthermore, if the related settings do not need to be modified at runtime, it is advisable not to store them in the settings at all. However, if storing them in settings is necessary, the sensitive values must be encrypted as described below.

    In addition, marking these values with the DisableAuditing attribute will prevent them from being included in audit logs. However, this alone does not prevent such values from being exposed to the client, for example via the AbpUserConfiguration service’s GetAll response.

    Therefore, for settings that should not be visible on the client side, you must properly configure the ClientVisibilityProvider and set the appropriate setting scope. This ensures that sensitive settings remain server-side only and are not exposed to the client.

    Related Document

    Example:

    await SettingManager.ChangeSettingForApplicationAsync(DataCollector.Sftp.Password,        SimpleStringCipher.Instance.Encrypt(settings.SftpPassword));
    

    Also example when defining the setting:

    new SettingDefinition(DataCollector.Sftp.Password,
        GetFromAppSettings(DataCollector.Sftp.Password, ""),
        clientVisibilityProvider: new HiddenSettingClientVisibilityProvider()),
    
    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)