ASP.NET Zero V13.3 or V14.1 /Controllers/TokenAuthController.cs Static code analysis tool Coverity reported the following issue: [HttpPost] public async Task<ExternalAuthenticateResultModel> ExternalAuthenticate( [FromBody] ExternalAuthenticateModel model)
An attacker could modify sensitive data or program variables.
In System.Threading.Tasks.Task`1<umsplus.Web.Models.TokenAuth.ExternalAuthenticateResultModel> umsplus.Web.Controllers.TokenAuthController::ExternalAuthenticate(umsplus.Web.Models.TokenAuth.ExternalAuthenticateModel): A sensitive property is automatically bound to the HTTP request parameters. (CWE-915)
3 Answer(s)
-
0
Hi @hongbing.wang
Thanks for your feedback. We have created an issue for this. You can follow the developments here.
As a temporary mitigation, you may avoid binding these sensitive fields directly by assigning them manually within the controller or by retrieving them securely from your authentication provider or internal flow.
Thank you
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hello @oguzhanagir, The above link is broken. Please provide an updated link or the status of your development. Has the issue been resolved? Thank you.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @hongbing.wang
- Go to https://aspnetzero.com and log in using the account associated with your license.
- Click the Account button in the top right navbar, then select Manage.
- On the account management page, go to the GitHub Members tab. This section lists the GitHub users with access to the private repository.
- If your GitHub username is not listed, you can add it here.
- If it’s already listed but access still isn’t working, try removing the user and adding it again.
If that doesn’t resolve the issue, please email [email protected] with your license/subscription details and your GitHub username. The team will assist you further.
As a result of the analysis conducted on this matter, the following conclusion has been reached:
Since we are using CORS, this endpoint can't be called from an external app. Also, all fields in the related input are used in related ExternalAuthenticate method. So, this seems like a false alarm.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image)
