-
Type:
Enhancement
-
Status: Closed
-
Priority:
High
-
Resolution: Done
-
Component/s: BenAdmin
-
Labels:None
-
Module:BenAdmin - Security
-
Reported by:Harbinger
-
Item State:Production Complete - Closed
Actual
If user enters url "https://wt-stage/Platform/common/UploadFilePost" then default Error page is displayed if we forcefully browse the URL without login.
Expected
User should redirect to Login Page
- is duplicated by
-
ST-232 Information Disclosure for File Upload URL
-
- Closed
-
Field | Original Value | New Value |
---|---|---|
Assignee | Vikas Pawar [ vikas.pawar ] |
Status | New Request [ 10029 ] | Pending for Approval [ 10002 ] |
Status | Pending for Approval [ 10002 ] | Approved for Development [ 10003 ] |
Status | Approved for Development [ 10003 ] | In Development [ 10007 ] |
Component/s | BenAdmin [ 10100 ] |
Module | Parent values: Platform(10106)Level 1 values: Security(10115) | Parent values: BenAdmin(10100) |
Module | Parent values: BenAdmin(10100) | Parent values: BenAdmin(10100)Level 1 values: Security(10112) |
Summary | Information Disclosure for File Upload URL | Security - Deny access to unauthorized users |
Description |
*Actual* Default Error page is displayed if we forcefully browse the URL without login. *Expected* Redirect to Login Page |
*Actual* If user enters url "https://wt-stage/Platform/common/UploadFilePost" then default Error page is displayed if we forcefully browse the URL without login. *Expected* User should redirect to Login Page |
Assignee | Vikas Pawar [ vikas.pawar ] | Vijayendra Shinde [ ID10506 ] |
Issue Category | EBS [ 10350 ] | Harbinger [ 10700 ] |
Assignee | Vijayendra Shinde [ ID10506 ] | Deepali Tidke [ deepalit ] |
Status | In Development [ 10007 ] | Local Testing [ 10200 ] |
Status | Local Testing [ 10200 ] | Pending for Stage Approval [ 10300 ] |
Status | Pending for Stage Approval [ 10300 ] | Approved for Stage [ 10030 ] |
Status | Approved for Stage [ 10030 ] | Stage Testing [ 10201 ] |
Status | Stage Testing [ 10201 ] | Pending for Production Approval [ 10301 ] |
Status | Pending for Production Approval [ 10301 ] | Approved for production [ 10034 ] |
Status | Approved for production [ 10034 ] | Production Testing [ 10202 ] |
Resolution | Fixed [ 1 ] | |
Status | Production Testing [ 10202 ] | Production Complete [ 10028 ] |
Item State | Parent values: Production Complete(10222)Level 1 values: Closed(10223) |
Status | Production Complete [ 10028 ] | Closed [ 6 ] |
Link | This issue relates to DEV-13718 [ DEV-13718 ] |
Transition | Time In Source Status | Execution Times |
---|
|
56s | 1 |
|
2s | 1 |
|
2s | 1 |
|
26d 19h 20m | 1 |
|
4s | 1 |
|
1s | 1 |
|
1s | 1 |
|
2s | 1 |
|
1s | 1 |
|
1s | 1 |
|
5s | 1 |
|
10s | 1 |
Denied access to unauthorized users in web.config