Details
-
Task
-
Resolution: Unresolved
-
Medium
-
None
-
None
-
AMRIT Sprint 28, AMRIT Sprint 29, AMRIT Sprint 30, AMRIT Sprint 35
-
FLW Mobile App
-
Prod
Description
Vulnerability Name: Swagger API Disclosure
- Vulnerable Point:
a. https://amritdemo.piramalswasthya.org/flw-0.0.1/swagger-ui.html
b. https://amritdemo.piramalswasthya.org/tmapi-v1.0/swagger-ui.html - Observation / Description: It was observed that the Swagger API was publicly disclosed.
- Impact: An attacker can gain access to Swagger API if it is publicly accessible, which can lead to security breach.
- Recommendation: Never disclose Swagger API publicly.
- Recommendation Solution:
a. It's an open source code, so Swagger can be disclose publicly;
b. or Turn off (remove/ disable) Swagger API publicly in Production Environment/ UAT/ App Build