-
Type:
Change Request
-
Status:
Closed
-
Priority:
Medium
-
Resolution:
Done
-
-
-
Module:
BenAdmin
- Security
-
-
Item State:
Production Complete
- Closed
-
Issue Importance:
Must Have
-
Vulnerability Description:
WORKTERRA provides an interface for sending emails to administrators and WORKTERRA's customer support system. The backend does not rate-limit or validate the destination of these emails.
Impact:
A malicious user could use WORKTERRA servers as a spam delivery platform.
Verification and Attack Information:
Praetorian verified this finding by intercepting requests to the endpoint responsible for sending emails. A malicious user can modify the destination email address to any email address. Additionally, there are no controls in place to the number of emails sent within a given time frame. This finding was demonstrated by sending 50 emails to a test email account. The figure below shows that the emails are originating from WORKTERRA IP addresses.
Recommendation:
Validate the email's destination address on the server-side. Additionally, WORKTERRA should limit the number of emails that a user can send per-minute.
- relates to
-
ST-211
Restrict domain user for emails
-
-
Closed
{"report":{"apdex":0.5,"isInitial":true,"journeyId":"653cf0dc-86d7-4de7-ba7a-736a2fc9eec7","key":"jira.project.issue.view-issue","navigationType":0,"readyForUser":1589.1999999955297,"redirectCount":0,"resourceLoadedEnd":1362.6000000014901,"resourceLoadedStart":172.19999999552965,"resourceTiming":[{"duration":274.6000000014901,"initiatorType":"link","name":"https://jira.workterra.net/s/3003653444a1e1a85555cab7dcfb3a21-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/2e46d90b5cae895c9c38649c9d510130/_/download/contextbatch/css/_super/batch.css","startTime":172.19999999552965,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":172.19999999552965,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":446.79999999701977,"responseStart":0,"secureConnectionStart":0},{"duration":273.6000000014901,"initiatorType":"link","name":"https://jira.workterra.net/s/dd6a0911920485696ac20493290df627-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/3abe50d469404b639745df44b51476b6/_/download/contextbatch/css/jira.browse.project,jira.view.issue,project.issue.navigator,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&richediton=true","startTime":173.29999999701977,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":173.29999999701977,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":446.8999999985099,"responseStart":0,"secureConnectionStart":0},{"duration":273.5,"initiatorType":"link","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/8.5.0/_/download/batch/com.atlassian.auiplugin:split_aui.pattern.label/com.atlassian.auiplugin:split_aui.pattern.label.css","startTime":173.39999999850988,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":173.39999999850988,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":446.8999999985099,"responseStart":0,"secureConnectionStart":0},{"duration":273.6000000014901,"initiatorType":"link","name":"https://jira.workterra.net/s/bd548f27bbf8f278bd83b60dd3284ed8-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:global-static-adgs/jira.webresources:global-static-adgs.css","startTime":173.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":173.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":447.1000000014901,"responseStart":0,"secureConnectionStart":0},{"duration":273.59999999403954,"initiatorType":"link","name":"https://jira.workterra.net/s/70725731a158a7140f19ddbd4201ba27-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:global-static/jira.webresources:global-static.css","startTime":173.60000000149012,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":173.60000000149012,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":447.19999999552965,"responseStart":0,"secureConnectionStart":0},{"duration":281.79999999701977,"initiatorType":"script","name":"https://jira.workterra.net/s/f2623af22c15df767ec6ff268ae0b8bd-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/2e46d90b5cae895c9c38649c9d510130/_/download/contextbatch/js/_super/batch.js?locale=en-US","startTime":173.60000000149012,"connectEnd":173.60000000149012,"connectStart":173.60000000149012,"domainLookupEnd":173.60000000149012,"domainLookupStart":173.60000000149012,"fetchStart":173.60000000149012,"redirectEnd":0,"redirectStart":0,"requestStart":173.60000000149012,"responseEnd":455.3999999985099,"responseStart":455.3999999985099,"secureConnectionStart":173.60000000149012},{"duration":303.8999999985099,"initiatorType":"script","name":"https://jira.workterra.net/s/ecf7ec549751ae117b778f0525d6d371-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/4.1.5/_/download/resources/com.atlassian.plugins.atlassian-chaperone:hotspot-tour/hotspot-tour.js?batch=false&locale=en-US","startTime":173.79999999701977,"connectEnd":173.79999999701977,"connectStart":173.79999999701977,"domainLookupEnd":173.79999999701977,"domainLookupStart":173.79999999701977,"fetchStart":173.79999999701977,"redirectEnd":0,"redirectStart":0,"requestStart":173.79999999701977,"responseEnd":477.69999999552965,"responseStart":477.69999999552965,"secureConnectionStart":173.79999999701977},{"duration":301.1000000014901,"initiatorType":"script","name":"https://jira.workterra.net/s/6ce676f2a5bcc9651cef6e7956f05def-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/3abe50d469404b639745df44b51476b6/_/download/contextbatch/js/jira.browse.project,jira.view.issue,project.issue.navigator,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en-US&richediton=true","startTime":173.79999999701977,"connectEnd":173.79999999701977,"connectStart":173.79999999701977,"domainLookupEnd":173.79999999701977,"domainLookupStart":173.79999999701977,"fetchStart":173.79999999701977,"redirectEnd":0,"redirectStart":0,"requestStart":173.79999999701977,"responseEnd":474.8999999985099,"responseStart":474.8999999985099,"secureConnectionStart":173.79999999701977},{"duration":304.70000000298023,"initiatorType":"script","name":"https://jira.workterra.net/s/6aa3fcf1fac5fd551eee0b69077524e6-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/aae1242f5fc81cc6a5bb8bc963ccda29/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en-US","startTime":173.89999999850988,"connectEnd":173.89999999850988,"connectStart":173.89999999850988,"domainLookupEnd":173.89999999850988,"domainLookupStart":173.89999999850988,"fetchStart":173.89999999850988,"redirectEnd":0,"redirectStart":0,"requestStart":173.89999999850988,"responseEnd":478.6000000014901,"responseStart":478.6000000014901,"secureConnectionStart":173.89999999850988},{"duration":305.29999999701977,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":174.10000000149012,"connectEnd":174.10000000149012,"connectStart":174.10000000149012,"domainLookupEnd":174.10000000149012,"domainLookupStart":174.10000000149012,"fetchStart":174.10000000149012,"redirectEnd":0,"redirectStart":0,"requestStart":174.10000000149012,"responseEnd":479.3999999985099,"responseStart":479.3999999985099,"secureConnectionStart":174.10000000149012},{"duration":306.20000000298023,"initiatorType":"script","name":"https://jira.workterra.net/s/ecf7ec549751ae117b778f0525d6d371-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/8.5.0/_/download/batch/com.atlassian.auiplugin:split_aui.pattern.label/com.atlassian.auiplugin:split_aui.pattern.label.js?locale=en-US","startTime":174.19999999552965,"connectEnd":174.19999999552965,"connectStart":174.19999999552965,"domainLookupEnd":174.19999999552965,"domainLookupStart":174.19999999552965,"fetchStart":174.19999999552965,"redirectEnd":0,"redirectStart":0,"requestStart":174.19999999552965,"responseEnd":480.3999999985099,"responseStart":480.3999999985099,"secureConnectionStart":174.19999999552965},{"duration":305.80000000447035,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":174.19999999552965,"connectEnd":174.19999999552965,"connectStart":174.19999999552965,"domainLookupEnd":174.19999999552965,"domainLookupStart":174.19999999552965,"fetchStart":174.19999999552965,"redirectEnd":0,"redirectStart":0,"requestStart":174.19999999552965,"responseEnd":480,"responseStart":480,"secureConnectionStart":174.19999999552965},{"duration":314,"initiatorType":"link","name":"https://jira.workterra.net/s/05c862146699bb029ceb0a489075e63b-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/bcd66e9a133a1b9f5fd14b56841e1c5b/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":174.29999999701977,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":174.29999999701977,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":488.29999999701977,"responseStart":0,"secureConnectionStart":0},{"duration":306.79999999701977,"initiatorType":"script","name":"https://jira.workterra.net/rest/api/1.0/shortcuts/805012/ea6f30d2bfdc99578bb23f4a5bac3ecd/shortcuts.js?context=issuenavigation&context=issueaction","startTime":174.39999999850988,"connectEnd":174.39999999850988,"connectStart":174.39999999850988,"domainLookupEnd":174.39999999850988,"domainLookupStart":174.39999999850988,"fetchStart":174.39999999850988,"redirectEnd":0,"redirectStart":0,"requestStart":174.39999999850988,"responseEnd":481.19999999552965,"responseStart":481.19999999552965,"secureConnectionStart":174.39999999850988},{"duration":338.8999999985099,"initiatorType":"link","name":"https://jira.workterra.net/s/9095228fa10daa2d3e3d7d5760c95e91-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/72477c22780abda5f51fe696920d843f/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-jira.view.issue,-project.issue.navigator/batch.css?jira.create.linked.issue=true&richediton=true","startTime":174.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":174.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":513.3999999985099,"responseStart":0,"secureConnectionStart":0},{"duration":307.29999999701977,"initiatorType":"script","name":"https://jira.workterra.net/s/c19a1b46e985d7fb85efaf27c8febfdd-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/72477c22780abda5f51fe696920d843f/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-jira.view.issue,-project.issue.navigator/batch.js?jira.create.linked.issue=true&locale=en-US&richediton=true","startTime":174.5,"connectEnd":174.5,"connectStart":174.5,"domainLookupEnd":174.5,"domainLookupStart":174.5,"fetchStart":174.5,"redirectEnd":0,"redirectStart":0,"requestStart":174.5,"responseEnd":481.79999999701977,"responseStart":481.79999999701977,"secureConnectionStart":174.5},{"duration":957.1000000014901,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":175.29999999701977,"connectEnd":175.29999999701977,"connectStart":175.29999999701977,"domainLookupEnd":175.29999999701977,"domainLookupStart":175.29999999701977,"fetchStart":175.29999999701977,"redirectEnd":0,"redirectStart":0,"requestStart":175.29999999701977,"responseEnd":1132.3999999985099,"responseStart":1132.3999999985099,"secureConnectionStart":175.29999999701977},{"duration":1187.1000000014901,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":175.5,"connectEnd":175.5,"connectStart":175.5,"domainLookupEnd":175.5,"domainLookupStart":175.5,"fetchStart":175.5,"redirectEnd":0,"redirectStart":0,"requestStart":175.5,"responseEnd":1362.6000000014901,"responseStart":1362.6000000014901,"secureConnectionStart":175.5},{"duration":665.6999999955297,"initiatorType":"xmlhttprequest","name":"https://jira.workterra.net/rest/webResources/1.0/resources","startTime":696.5,"connectEnd":696.5,"connectStart":696.5,"domainLookupEnd":696.5,"domainLookupStart":696.5,"fetchStart":696.5,"redirectEnd":0,"redirectStart":0,"requestStart":696.5,"responseEnd":1362.1999999955297,"responseStart":1362.1999999955297,"secureConnectionStart":696.5}],"threshold":1000,"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":77,"responseStart":157,"responseEnd":158,"domLoading":170,"domInteractive":1469,"domContentLoadedEventStart":1469,"domContentLoadedEventEnd":1598,"domComplete":1890,"loadEventStart":1890,"loadEventEnd":1893,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1393.6999999955297},{"name":"bigPipe.sidebar-id.end","time":1394.6999999955297},{"name":"bigPipe.activity-panel-pipe-id.start","time":1395.1999999955297},{"name":"bigPipe.activity-panel-pipe-id.end","time":1398.1000000014901}],"measures":[],"correlationId":"495ed5a3681443","effectiveType":"4g","downlink":9.5,"rtt":0,"serverDuration":48,"dbReadsTimeInMs":4,"dbConnsTimeInMs":4,"applicationHash":"156decd7d2b4272533aa6cefc8294af635e1da97","experiments":[]}}
Hi Venkatesh Pujari
I have checked it on CSS for HSPL company employee and it is working correctly.
Please verify again.