-
Type:
Bug
-
Status: Closed
-
Priority:
High
-
Resolution: Bug Fixed
-
Affects Version/s: None
-
Fix Version/s: None
-
Component/s: UI Refresh
-
Labels:None
-
Environment:Pre Production
-
Bug Type:Functional
-
Bug Severity:Medium
-
Level:Employee
-
Module:BenAdmin - Security
-
Reported by:Harbinger
-
Company:All Clients/Multiple Clients
-
Item State:Stage QA - Production Deployment on Hold
-
Issue Importance:Q2
All Company- Employee Login - URL parameters - Security - URL parameter values in all the SSM pages,reports are displayed in plain text.
As observed all the URL parameter values are displayed in plain english text and can be vulnerable for security breach.
This can be generic issue and may exist for Admin,Partners,SA user roles too.
CC : Vijayendra ShindeSachin HingoleRakesh RoyHrishikesh DeshpandeRohan J KhandaveSamir
- relates to
-
NF-2714 Vulnerability Assessment and Penetration Testing for Workterra on Azure US environment.
-
- To Do
-
Field | Original Value | New Value |
---|---|---|
Status | Open [ 1 ] | In Development [ 10007 ] |
Assignee | Vijayendra Shinde [ ID10506 ] | Prasad Pise [ prasadp ] |
Resolution | System Behaviour [ 10100 ] | |
Status | In Development [ 10007 ] | Rejected [ 10004 ] |
Status | Rejected [ 10004 ] | Closed [ 6 ] |
Module | Parent values: BenAdmin(10100) | Parent values: BenAdmin(10100)Level 1 values: Security(10112) |
Status | Closed [ 6 ] | Reopen in Production [ 10027 ] |
Assignee | Prasad Pise [ prasadp ] | Vijayendra Shinde [ ID10506 ] |
Attachment | ParameterURL.jpg [ 71722 ] |
Bug Severity | Medium [ 16702 ] | |
Company | All Clients/Multiple Clients [ 18434 ] | |
Environment | Pre Production [ 18470 ] | |
Priority | Highest [ 1 ] | High [ 2 ] |
Assignee | Vijayendra Shinde [ ID10506 ] | Pratap Patil [ pratap.patil ] |
Status | Reopen in Production [ 10027 ] | In Development [ 10007 ] |
Item State | Parent values: Development(10200)Level 1 values: In Progress(10206) |
Code Reviewed By | Vijayendra Shinde [ 11901 ] |
Item State | Parent values: Development(10200)Level 1 values: In Progress(10206) | Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209) |
Assignee | Pratap Patil [ pratap.patil ] | Prasad Pise [ prasadp ] |
Item State | Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209) | Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) |
Remaining Estimate | 0h [ 0 ] | |
Time Spent | 5h [ 18000 ] | |
Worklog Id | 105454 [ 105454 ] |
Status | In Development [ 10007 ] | Local Testing [ 10200 ] |
Item State | Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) | Parent values: LB QA(10201)Level 1 values: In Testing(10210) |
Time Spent | 5h [ 18000 ] | 6h [ 21600 ] |
Worklog Id | 105996 [ 105996 ] |
Item State | Parent values: LB QA(10201)Level 1 values: In Testing(10210) | Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) |
Status | Local Testing [ 10200 ] | Stage Testing [ 10201 ] |
Item State | Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) | Parent values: Stage QA(10202)Level 1 values: In Testing(10214) |
Time Spent | 6h [ 21600 ] | 6.5h [ 23400 ] |
Worklog Id | 106091 [ 106091 ] |
Time Spent | 6.5h [ 23400 ] | 13.5h [ 48600 ] |
Worklog Id | 106153 [ 106153 ] |
Item State | Parent values: Stage QA(10202)Level 1 values: In Testing(10214) | Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) |
Time Spent | 13.5h [ 48600 ] | 15.5h [ 55800 ] |
Worklog Id | 106279 [ 106279 ] |
Time Spent | 15.5h [ 55800 ] | 17.5h [ 63000 ] |
Worklog Id | 106333 [ 106333 ] |
Item State | Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) | Parent values: LB QA(10201)Level 1 values: In Testing(10210) |
Item State | Parent values: LB QA(10201)Level 1 values: In Testing(10210) | Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) |
Attachment | EmpBen.jpg [ 73844 ] |
Time Spent | 17.5h [ 63000 ] | 19.5h [ 70200 ] |
Worklog Id | 106484 [ 106484 ] |
Assignee | Prasad Pise [ prasadp ] | Komal Barde [ komal.barde ] |
Resolution | System Behaviour [ 10100 ] | Unresolved [ 10200 ] |
Status | Stage Testing [ 10201 ] | Reopen in Stage [ 10023 ] |
Item State | Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) | Parent values: Stage QA(10202)Level 1 values: Re-open(10216) |
Item State | Parent values: Stage QA(10202)Level 1 values: Re-open(10216) | Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) |
Assignee | Komal Barde [ komal.barde ] | Prasad Pise [ prasadp ] |
Item State | Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) | Parent values: LB QA(10201)Level 1 values: In Testing(10210) |
Item State | Parent values: LB QA(10201)Level 1 values: In Testing(10210) | Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213) |
Item State | Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213) | Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) |
Status | Reopen in Stage [ 10023 ] | In Development [ 10007 ] |
Status | In Development [ 10007 ] | Local Testing [ 10200 ] |
Status | Local Testing [ 10200 ] | Stage Testing [ 10201 ] |
Item State | Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) | Parent values: Stage QA(10202)Level 1 values: In Testing(10214) |
Item State | Parent values: Stage QA(10202)Level 1 values: In Testing(10214) | Parent values: Stage QA(10202)Level 1 values: Production Deployment on Hold(10224) |
Time Spent | 19.5h [ 70200 ] | 22.5h [ 81000 ] |
Worklog Id | 106674 [ 106674 ] |
Time Spent | 22.5h [ 81000 ] | 24.5h [ 88200 ] |
Worklog Id | 106781 [ 106781 ] |
Status | Stage Testing [ 10201 ] | Production Testing [ 10202 ] |
Resolution | Unresolved [ 10200 ] | Bug Fixed [ 10402 ] |
Status | Production Testing [ 10202 ] | Production Complete [ 10028 ] |
Time Spent | 24.5h [ 88200 ] | 26.5h [ 95400 ] |
Worklog Id | 109208 [ 109208 ] |
Status | Production Complete [ 10028 ] | Closed [ 6 ] |
Link | This issue relates to DEV-13718 [ DEV-13718 ] |