You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Validate the endpoint URI self-registered by BPN Discovery in the Backend: Change of endpoint URI should be approved by partner (e.g., by pattern matching or by two-man rule).
If the attacker has read access to discoveryfinder, they can manipulate the entries (like endpoint), so at the end the enduser can redirected to wrong endpoint.
We can think about an validation in discoveryfinder to allow only specificed domains.
The text was updated successfully, but these errors were encountered:
There are some low/medium risks for the security assessments.
https://confluence.catena-x.net/pages/viewpage.action?pageId=81713190
One the the medium risk is THREAT-003:
Validate the endpoint URI self-registered by BPN Discovery in the Backend: Change of endpoint URI should be approved by partner (e.g., by pattern matching or by two-man rule).
If the attacker has read access to discoveryfinder, they can manipulate the entries (like endpoint), so at the end the enduser can redirected to wrong endpoint.
We can think about an validation in discoveryfinder to allow only specificed domains.
The text was updated successfully, but these errors were encountered: