Uploaded image for project: 'Crucible'
  1. Crucible
  2. CRUC-4625

Wrong HTTP response codes leak information

    XMLWordPrintable

Details

    Description

      There are some resources exposed in FeCru where depending on their existence user may get 403 or 404 http response code depending on the existence of the resource. Because the permission check is done earlier than existence check, server may leak the existence of particular resource to the requestor, even when the requestor doesn't have permission to access that resource.
      Current behaviour seems more in line with definitions of the HTTP 403 and 404 status codes (see RFC 2616), but allows information leak.

      Attachments

        Issue Links

          Activity

            People

              kcichy Kamil Cichy
              alyons Anna Lyons [Atlassian]
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: