Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Assessment: THREAT-003 (Validation of endpoints/detection of compromised paths) #87

Open
RazvanZmau opened this issue Jan 15, 2024 · 0 comments
Assignees

Comments

@RazvanZmau
Copy link

There are some low/medium risks for the security assessments.

https://confluence.catena-x.net/pages/viewpage.action?pageId=81713190

One the the medium risk is THREAT-003:

Validate the endpoint URI self-registered by BPN Discovery in the Backend: Change of endpoint URI should be approved by partner (e.g., by pattern matching or by two-man rule).

If the attacker has read access to discoveryfinder, they can manipulate the entries (like endpoint), so at the end the enduser can redirected to wrong endpoint.

We can think about an validation in discoveryfinder to allow only specificed domains.

@RazvanZmau RazvanZmau moved this to Todo in 🚀SLDT Board Jan 15, 2024
@thomas-henn thomas-henn assigned tunacicek and unassigned agg3fe Jul 10, 2024
@tunacicek tunacicek moved this from Todo to In Progress in 🚀SLDT Board Jul 11, 2024
@tunacicek tunacicek moved this from In Progress to Todo in 🚀SLDT Board Jul 11, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: Todo
Development

No branches or pull requests

3 participants