Uploaded image for project: 'AMRIT'
  1. AMRIT
  2. AMM-1186

Handling Swagger API Disclosure issue in FLW App

    XMLWordPrintable

Details

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Medium Medium
    • None
    • None
    • AMRIT Sprint 28, AMRIT Sprint 29, AMRIT Sprint 30, AMRIT Sprint 35
    • FLW Mobile App
    • Prod

    Description

      Vulnerability Name: Swagger API Disclosure

      1. Vulnerable Point:
        a. https://amritdemo.piramalswasthya.org/flw-0.0.1/swagger-ui.html
        b. https://amritdemo.piramalswasthya.org/tmapi-v1.0/swagger-ui.html
      2. Observation / Description: It was observed that the Swagger API was publicly disclosed.
      3. Impact: An attacker can gain access to Swagger API if it is publicly accessible, which can lead to security breach.
      4. Recommendation: Never disclose Swagger API publicly.
      5. Recommendation Solution:
        a. It's an open source code, so Swagger can be disclose publicly;
        b. or Turn off (remove/ disable) Swagger API publicly in Production Environment/ UAT/ App Build

      Attachments

        Forms

          Activity

            People

              ravi.shanigarapu@piramalswasthya.org Ravi Shanigarapu
              madhava.ramu@piramalswasthya.org Madhava Ramu N
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:

                Time Tracking

                  Estimated:
                  Original Estimate - 0 minutes
                  0m
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 1 day
                  1d

                  CucumberStudio

                    CucumberStudio data loading...