-
Type:
Task
-
Resolution: Done
-
Priority:
Medium
-
Affects Version/s: None
-
AMRIT Sprint 28, AMRIT Sprint 29, AMRIT Sprint 30, AMRIT Sprint 35, AMRIT Sprint 39
-
FLW Mobile App
-
Prod
Vulnerability Name: Swagger API Disclosure
- Vulnerable Point:
a. https://amritdemo.piramalswasthya.org/flw-0.0.1/swagger-ui.html
b. https://amritdemo.piramalswasthya.org/tmapi-v1.0/swagger-ui.html - Observation / Description: It was observed that the Swagger API was publicly disclosed.
- Impact: An attacker can gain access to Swagger API if it is publicly accessible, which can lead to security breach.
- Recommendation: Never disclose Swagger API publicly.
- Recommendation Solution:
a. It's an open source code, so Swagger can be disclose publicly;
b. or Turn off (remove/ disable) Swagger API publicly in Production Environment/ UAT/ App Build