Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-12869

[Security]: Stack Trace displayed when the report link is copied from one browser to another.

    Details

    • Type: Bug
    • Status: Open
    • Priority: High
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: None
    • Labels:
      None
    • Environment:
      Pre Production
    • Bug Severity:
      Medium
    • Module:
      BenAdmin - Security
    • Reported by:
      Harbinger
    • Company:
      All Clients/Multiple Clients
    • Item State:
      Development - On Hold
    • Mobile Platform :
      Web Service

      Description

      Steps to Repro:

      1. Login to pre-production environment with partner credentials.
      2. Navigate to BenAdmin->Reports->Static Reports
      3. Run any report under the static reports.
      4. Copy the link launched in the new tab.
      5. Paste this link in another browser other than the one used to launch the report and hit enter.
      6. ex: if logged chrome is used to launch the report then copy the report link in IE, Edge or Firefox.

      Actual Result: Stack trace is displayed on the screen with functions/methods getting exposed.
      Expected Result: Login page should be displayed since the application link is launched in another browser. Also, the session should not be maintained across different browsers.

      Please refer to attached error screenshot.

      CC: Prasad Pise Rakesh Roy Samir Vijayendra Shinde Bharti Satpute

        Attachments

          Activity

          Hide
          santosh.balid Santosh Balid (Inactive) added a comment -

          Please plan it in future sprints.

          Cc : Satya, Jaideep Vinchurkar, Bharti Satpute

          Show
          santosh.balid Santosh Balid (Inactive) added a comment - Please plan it in future sprints. Cc : Satya , Jaideep Vinchurkar , Bharti Satpute

            People

            Assignee:
            gaurav.sodani Gaurav Sodani (Inactive)
            Reporter:
            anirudha.joshi anirudha joshi (Inactive)
            QA:
            anirudha joshi (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Dates

              Created:
              Updated: