Base solution for your next web application
Open Closed

A sensitive property is automatically bound to the HTTP request parameters #12480


User avatar
0
hongbing.wang created

ASP.NET Zero V13.3 or V14.1 /Controllers/TokenAuthController.cs Static code analysis tool Coverity reported the following issue: [HttpPost] public async Task<ExternalAuthenticateResultModel> ExternalAuthenticate( [FromBody] ExternalAuthenticateModel model)

An attacker could modify sensitive data or program variables.

In System.Threading.Tasks.Task`1<umsplus.Web.Models.TokenAuth.ExternalAuthenticateResultModel> umsplus.Web.Controllers.TokenAuthController::ExternalAuthenticate(umsplus.Web.Models.TokenAuth.ExternalAuthenticateModel): A sensitive property is automatically bound to the HTTP request parameters. (CWE-915)

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

3 Answer(s)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @hongbing.wang

    Thanks for your feedback. We have created an issue for this. You can follow the developments here.

    As a temporary mitigation, you may avoid binding these sensitive fields directly by assigning them manually within the controller or by retrieving them securely from your authentication provider or internal flow.

    Thank you

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    hongbing.wang created

    Hello @oguzhanagir, The above link is broken. Please provide an updated link or the status of your development. Has the issue been resolved? Thank you.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi @hongbing.wang

    • Go to https://aspnetzero.com and log in using the account associated with your license.
    • Click the Account button in the top right navbar, then select Manage.
    • On the account management page, go to the GitHub Members tab. This section lists the GitHub users with access to the private repository.
    • If your GitHub username is not listed, you can add it here.
    • If it’s already listed but access still isn’t working, try removing the user and adding it again.

    If that doesn’t resolve the issue, please email [email protected] with your license/subscription details and your GitHub username. The team will assist you further.

    As a result of the analysis conducted on this matter, the following conclusion has been reached:

    Since we are using CORS, this endpoint can't be called from an external app. Also, all fields in the related input are used in related ExternalAuthenticate method. So, this seems like a false alarm.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)