Type:
Bug
Status:
In LB Testing
Priority:
High
Resolution:
Unresolved
Affects Version/s:
None
Fix Version/s:
None
Module:
Platform
- Security
Item State:
Development
- On Hold
[Security] All Company - EE Login - Enroll Now - Request parameters values on Enroll Now page get altered and can be saved successfully.
Environment : Azure
Login : Employee
Company : Beta Security Test
Employee : Saba Abai / 164215 / Password1@
Tool : ZAP
Replication Steps:
1. Login as Employee
2. Start traversing employee self serve mode through OE/New Hire/Employee Dashboard -> Enroll Now
3. Go to Enroll Now page
4. Go to any plan which is already enrolled or enroll in new plan.
5. Tamper the request parameters like Coverage Amount, Costs for enroll now action.
6. Save the updated values.
7. Verify the Confirmation Statement, Enrollment Summary, Enrollment reports
Real life scenarios those are possible.
1. Employee can increase the Coverage amount keeping the cost (Premium) same.
2. Employee can increase Coverage amount and decrease cost (Premium).
3. Employee can keep same Coverage amount for decreased cost (Premium).
CC : Rakesh Roy Samir Bharti Satpute Vijay Siddha Satya Sachin Hingole Hrishikesh Deshpande Gaurav Sodani Nidhi Kaul shyam sharma
relates to
NF-2714
Vulnerability Assessment and Penetration Testing for Workterra on Azure US environment.
To Do
Rohan J Khandave (Inactive)
made changes -
26/Jul/17 10:01 AM
Item State
Parent values: Development(10200)Level 1 values: In Analysis(10204)
Remaining Estimate
24h
[ 86400
]
Original Estimate
24h
[ 86400
]
Rohan J Khandave (Inactive)
made changes -
26/Jul/17 03:16 PM
Remaining Estimate
24h
[ 86400
]
21h
[ 75600
]
Time Spent
3h
[ 10800
]
Worklog Id
66661
[ 66661
]
Rohan J Khandave (Inactive)
made changes -
28/Jul/17 01:16 PM
Remaining Estimate
21h
[ 75600
]
18.5h
[ 66600
]
Time Spent
3h
[ 10800
]
5.5h
[ 19800
]
Worklog Id
67756
[ 67756
]
Rohan J Khandave (Inactive)
made changes -
31/Jul/17 07:42 AM
Item State
Parent values: Development(10200)Level 1 values: In Analysis(10204)
Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209)
Rohan J Khandave (Inactive)
made changes -
31/Jul/17 07:42 AM
Code Review Date
31/Jul/2017
Code Reviewed By
Vijayendra Shinde
[ 11901
]
Developer
Rohan J Khandave
[ rohan.khandave
]
Rohan J Khandave (Inactive)
made changes -
31/Jul/17 07:43 AM
Remaining Estimate
18.5h
[ 66600
]
17h
[ 61200
]
Time Spent
5.5h
[ 19800
]
7h
[ 25200
]
Worklog Id
68119
[ 68119
]
Rohan J Khandave (Inactive)
made changes -
31/Jul/17 02:00 PM
Remaining Estimate
17h
[ 61200
]
15h
[ 54000
]
Time Spent
7h
[ 25200
]
9h
[ 32400
]
Worklog Id
68520
[ 68520
]
Ashwin Wankhede (Inactive)
made changes -
01/Aug/17 08:54 AM
Item State
Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209)
Parent values: LB QA(10201)Level 1 values: LB Deployed(11600)
Prasad Pise (Inactive)
made changes -
02/Aug/17 07:31 AM
Item State
Parent values: LB QA(10201)Level 1 values: LB Deployed(11600)
Parent values: LB QA(10201)Level 1 values: In Testing(10210)
Prasad Pise (Inactive)
made changes -
02/Aug/17 07:31 AM
Item State
Parent values: LB QA(10201)Level 1 values: In Testing(10210)
Parent values: LB QA(10201)Level 1 values: Re-open(10212)
Prasad Pise (Inactive)
made changes -
02/Aug/17 07:34 AM
Assignee
Prasad Pise
[ prasadp
]
Rohan J Khandave
[ rohan.khandave
]
Prasad Pise (Inactive)
made changes -
02/Aug/17 11:04 AM
Remaining Estimate
15h
[ 54000
]
13.5h
[ 48600
]
Time Spent
9h
[ 32400
]
10.5h
[ 37800
]
Worklog Id
68931
[ 68931
]
Prasad Pise (Inactive)
made changes -
02/Aug/17 01:47 PM
Remaining Estimate
13.5h
[ 48600
]
12.5h
[ 45000
]
Time Spent
10.5h
[ 37800
]
11.5h
[ 41400
]
Worklog Id
69034
[ 69034
]
Prasad Pise (Inactive)
made changes -
03/Aug/17 12:56 PM
Remaining Estimate
12.5h
[ 45000
]
10.5h
[ 37800
]
Time Spent
11.5h
[ 41400
]
13.5h
[ 48600
]
Worklog Id
69222
[ 69222
]
Prasad Pise (Inactive)
made changes -
04/Jan/18 04:32 AM
Assignee
Prasad Pise
[ prasadp
]
Santosh Balid
[ santosh.balid
]
Santosh Balid (Inactive)
made changes -
16/Jan/18 05:43 AM
Item State
Parent values: LB QA(10201)Level 1 values: Re-open(10212)
Parent values: Development(10200)Level 1 values: On Hold(10207)
Santosh Balid (Inactive)
made changes -
16/Jan/18 01:20 PM
Assignee
Santosh Balid
[ santosh.balid
]
Gaurav Sodani
[ gaurav.sodani
]
Transition
Time In Source Status
Execution Times
Open
In Development
6d 4h 14m
1
In Development
In LB Testing
4d 21h 43m
1
{"report":{"apdex":0.5,"isInitial":true,"journeyId":"5a72be5e-e671-4729-8ad6-f38ef7861431","key":"jira.project.issue.view-issue","navigationType":0,"readyForUser":1042.300000011921,"redirectCount":0,"resourceLoadedEnd":1284.5,"resourceLoadedStart":231.10000002384186,"resourceTiming":[{"duration":324.39999997615814,"initiatorType":"link","name":"https://jira.workterra.net/s/3003653444a1e1a85555cab7dcfb3a21-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/2e46d90b5cae895c9c38649c9d510130/_/download/contextbatch/css/_super/batch.css","startTime":231.10000002384186,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":231.10000002384186,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":555.5,"responseStart":0,"secureConnectionStart":0},{"duration":372.7000000476837,"initiatorType":"link","name":"https://jira.workterra.net/s/dd6a0911920485696ac20493290df627-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/3abe50d469404b639745df44b51476b6/_/download/contextbatch/css/jira.browse.project,jira.view.issue,project.issue.navigator,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&richediton=true","startTime":231.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":231.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":604.2000000476837,"responseStart":0,"secureConnectionStart":0},{"duration":372.80000001192093,"initiatorType":"link","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/8.5.0/_/download/batch/com.atlassian.auiplugin:split_aui.pattern.label/com.atlassian.auiplugin:split_aui.pattern.label.css","startTime":231.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":231.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":604.3000000119209,"responseStart":0,"secureConnectionStart":0},{"duration":373,"initiatorType":"link","name":"https://jira.workterra.net/s/bd548f27bbf8f278bd83b60dd3284ed8-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:global-static-adgs/jira.webresources:global-static-adgs.css","startTime":231.60000002384186,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":231.60000002384186,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":604.6000000238419,"responseStart":0,"secureConnectionStart":0},{"duration":372.80000001192093,"initiatorType":"link","name":"https://jira.workterra.net/s/70725731a158a7140f19ddbd4201ba27-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:global-static/jira.webresources:global-static.css","startTime":231.80000001192093,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":231.80000001192093,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":604.6000000238419,"responseStart":0,"secureConnectionStart":0},{"duration":381.80000001192093,"initiatorType":"script","name":"https://jira.workterra.net/s/f2623af22c15df767ec6ff268ae0b8bd-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/2e46d90b5cae895c9c38649c9d510130/_/download/contextbatch/js/_super/batch.js?locale=en-US","startTime":231.80000001192093,"connectEnd":231.80000001192093,"connectStart":231.80000001192093,"domainLookupEnd":231.80000001192093,"domainLookupStart":231.80000001192093,"fetchStart":231.80000001192093,"redirectEnd":0,"redirectStart":0,"requestStart":231.80000001192093,"responseEnd":613.6000000238419,"responseStart":613.6000000238419,"secureConnectionStart":231.80000001192093},{"duration":408.7000000476837,"initiatorType":"script","name":"https://jira.workterra.net/s/ecf7ec549751ae117b778f0525d6d371-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/4.1.5/_/download/resources/com.atlassian.plugins.atlassian-chaperone:hotspot-tour/hotspot-tour.js?batch=false&locale=en-US","startTime":232,"connectEnd":232,"connectStart":232,"domainLookupEnd":232,"domainLookupStart":232,"fetchStart":232,"redirectEnd":0,"redirectStart":0,"requestStart":232,"responseEnd":640.7000000476837,"responseStart":640.7000000476837,"secureConnectionStart":232},{"duration":405.60000002384186,"initiatorType":"script","name":"https://jira.workterra.net/s/6ce676f2a5bcc9651cef6e7956f05def-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/3abe50d469404b639745df44b51476b6/_/download/contextbatch/js/jira.browse.project,jira.view.issue,project.issue.navigator,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en-US&richediton=true","startTime":232,"connectEnd":232,"connectStart":232,"domainLookupEnd":232,"domainLookupStart":232,"fetchStart":232,"redirectEnd":0,"redirectStart":0,"requestStart":232,"responseEnd":637.6000000238419,"responseStart":637.6000000238419,"secureConnectionStart":232},{"duration":408.89999997615814,"initiatorType":"script","name":"https://jira.workterra.net/s/6aa3fcf1fac5fd551eee0b69077524e6-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/aae1242f5fc81cc6a5bb8bc963ccda29/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en-US","startTime":232.20000004768372,"connectEnd":232.20000004768372,"connectStart":232.20000004768372,"domainLookupEnd":232.20000004768372,"domainLookupStart":232.20000004768372,"fetchStart":232.20000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":232.20000004768372,"responseEnd":641.1000000238419,"responseStart":641.1000000238419,"secureConnectionStart":232.20000004768372},{"duration":409.19999998807907,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":232.30000001192093,"connectEnd":232.30000001192093,"connectStart":232.30000001192093,"domainLookupEnd":232.30000001192093,"domainLookupStart":232.30000001192093,"fetchStart":232.30000001192093,"redirectEnd":0,"redirectStart":0,"requestStart":232.30000001192093,"responseEnd":641.5,"responseStart":641.5,"secureConnectionStart":232.30000001192093},{"duration":409.5,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":232.4000000357628,"connectEnd":232.4000000357628,"connectStart":232.4000000357628,"domainLookupEnd":232.4000000357628,"domainLookupStart":232.4000000357628,"fetchStart":232.4000000357628,"redirectEnd":0,"redirectStart":0,"requestStart":232.4000000357628,"responseEnd":641.9000000357628,"responseStart":641.9000000357628,"secureConnectionStart":232.4000000357628},{"duration":409.7000000476837,"initiatorType":"script","name":"https://jira.workterra.net/s/ecf7ec549751ae117b778f0525d6d371-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/8.5.0/_/download/batch/com.atlassian.auiplugin:split_aui.pattern.label/com.atlassian.auiplugin:split_aui.pattern.label.js?locale=en-US","startTime":232.5,"connectEnd":232.5,"connectStart":232.5,"domainLookupEnd":232.5,"domainLookupStart":232.5,"fetchStart":232.5,"redirectEnd":0,"redirectStart":0,"requestStart":232.5,"responseEnd":642.2000000476837,"responseStart":642.2000000476837,"secureConnectionStart":232.5},{"duration":410.5,"initiatorType":"link","name":"https://jira.workterra.net/s/05c862146699bb029ceb0a489075e63b-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/bcd66e9a133a1b9f5fd14b56841e1c5b/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":232.60000002384186,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":232.60000002384186,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":643.1000000238419,"responseStart":0,"secureConnectionStart":0},{"duration":409.89999997615814,"initiatorType":"script","name":"https://jira.workterra.net/rest/api/1.0/shortcuts/805012/81da1c7492d7ee698ae1cc31902498d9/shortcuts.js?context=issuenavigation&context=issueaction","startTime":232.70000004768372,"connectEnd":232.70000004768372,"connectStart":232.70000004768372,"domainLookupEnd":232.70000004768372,"domainLookupStart":232.70000004768372,"fetchStart":232.70000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":232.70000004768372,"responseEnd":642.6000000238419,"responseStart":642.6000000238419,"secureConnectionStart":232.70000004768372},{"duration":410.19999998807907,"initiatorType":"link","name":"https://jira.workterra.net/s/9095228fa10daa2d3e3d7d5760c95e91-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/72477c22780abda5f51fe696920d843f/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-jira.view.issue,-project.issue.navigator/batch.css?jira.create.linked.issue=true&richediton=true","startTime":233.10000002384186,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":233.10000002384186,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":643.3000000119209,"responseStart":0,"secureConnectionStart":0},{"duration":410,"initiatorType":"script","name":"https://jira.workterra.net/s/c19a1b46e985d7fb85efaf27c8febfdd-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/72477c22780abda5f51fe696920d843f/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-jira.view.issue,-project.issue.navigator/batch.js?jira.create.linked.issue=true&locale=en-US&richediton=true","startTime":233.20000004768372,"connectEnd":233.20000004768372,"connectStart":233.20000004768372,"domainLookupEnd":233.20000004768372,"domainLookupStart":233.20000004768372,"fetchStart":233.20000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":233.20000004768372,"responseEnd":643.2000000476837,"responseStart":643.2000000476837,"secureConnectionStart":233.20000004768372},{"duration":670.5,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":234.80000001192093,"connectEnd":234.80000001192093,"connectStart":234.80000001192093,"domainLookupEnd":234.80000001192093,"domainLookupStart":234.80000001192093,"fetchStart":234.80000001192093,"redirectEnd":0,"redirectStart":0,"requestStart":234.80000001192093,"responseEnd":905.3000000119209,"responseStart":905.3000000119209,"secureConnectionStart":234.80000001192093}],"threshold":1000,"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":35,"responseStart":224,"responseEnd":228,"domLoading":228,"domInteractive":1342,"domContentLoadedEventStart":1342,"domContentLoadedEventEnd":1406,"domComplete":2065,"loadEventStart":2065,"loadEventEnd":2067,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[],"measures":[],"correlationId":"4976b8dd43dde8","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":157,"dbReadsTimeInMs":30,"dbConnsTimeInMs":37,"applicationHash":"156decd7d2b4272533aa6cefc8294af635e1da97","experiments":[]}}
Please check after next azure deployment.