Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-12154

Security alerts reported during ZAP Spidering of the production application with partner login

    Details

    • Type: Bug
    • Status: Open
    • Priority: Medium
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: None
    • Labels:
      None
    • Environment:
      Production
    • Bug Type:
      Functional
    • Bug Severity:
      Medium
    • Module:
      Platform - Security
    • Reported by:
      Harbinger
    • Company:
      All Clients/Multiple Clients
    • Item State:
      Development - On Hold

      Description

      Scenario Traversed:

      • Login with partner credentials.
      • Select security testing company 'Beta testing 1'
      • Navigate to Search employee and select any test employee.
      • Navigate to Change employee password.
      • Change the password of selected employee.
      • Logout from the application.

      Attached is the penetration test report of spidering above mentioned workflow from OWASP ZAP.

      We have observed that the alerts under 'Low' category need to be addressed.

      Satya Can you please assign this ticket to concerned developer.

      Prasad Pise Samir Rakesh Roy

        Attachments

          Activity

          anirudha.joshi anirudha joshi (Inactive) created issue -
          satyap Satya made changes -
          Field Original Value New Value
          Assignee Satya [ ID10004 ] Santosh Balid [ santosh.balid ]
          anirudha.joshi anirudha joshi (Inactive) made changes -
          Attachment EnrollNowWithPartnerLogin.html [ 67884 ]
          anirudha.joshi anirudha joshi (Inactive) made changes -
          Attachment StaticReport_Spider.html [ 67885 ]
          santosh.balid Santosh Balid (Inactive) made changes -
          Remaining Estimate 0h [ 0 ]
          Time Spent 1h [ 3600 ]
          Worklog Id 92510 [ 92510 ]
          santosh.balid Santosh Balid (Inactive) made changes -
          Item State Parent values: Development(10200)Level 1 values: In Analysis(10204)
          Original Estimate 0h [ 0 ]
          santosh.balid Santosh Balid (Inactive) made changes -
          Time Spent 1h [ 3600 ] 3h [ 10800 ]
          Worklog Id 92761 [ 92761 ]
          santosh.balid Santosh Balid (Inactive) made changes -
          Attachment InternalErrorScreen.jpg [ 68778 ]
          santosh.balid Santosh Balid (Inactive) made changes -
          Time Spent 3h [ 10800 ] 10h [ 36000 ]
          Worklog Id 93458 [ 93458 ]
          santosh.balid Santosh Balid (Inactive) made changes -
          Time Spent 10h [ 36000 ] 14h [ 50400 ]
          Worklog Id 93992 [ 93992 ]
          santosh.balid Santosh Balid (Inactive) made changes -
          Time Spent 14h [ 50400 ] 18h [ 64800 ]
          Worklog Id 94332 [ 94332 ]
          santosh.balid Santosh Balid (Inactive) made changes -
          Item State Parent values: Development(10200)Level 1 values: In Analysis(10204) Parent values: Development(10200)Level 1 values: On Hold(10207)
          santosh.balid Santosh Balid (Inactive) made changes -
          Assignee Santosh Balid [ santosh.balid ] Gaurav Sodani [ gaurav.sodani ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Link This issue relates to DEV-13718 [ DEV-13718 ]

            People

            Assignee:
            gaurav.sodani Gaurav Sodani (Inactive)
            Reporter:
            anirudha.joshi anirudha joshi (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Dates

              Created:
              Updated:

                Time Tracking

                Estimated:
                Original Estimate - 0h
                0h
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 18h
                18h