I can see entity names I am not authorized to see

XMLWordPrintable

    • Type: Security Report
    • Resolution: Unresolved
    • Priority: L3 - Default
    • None
    • Affects Version/s: None
    • Component/s: backend
    • None
    • 4
    • Not defined

      Reproduce:

      • Obtain the url displaying the entity you are not authorized to access.
      • Go to this url

      Expected:

      • There is no information about the entity leaked

      Observed:

      • The breadcrumb in the header contains the name of the entity

       

      This is based on the GET /api/entities/names endpoint

            Assignee:
            Unassigned
            Reporter:
            Sebastian Stamm
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: