You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I noticed that this issue is similar to #3598 and this one is older, so I'm adding a comment here.
My team noticed this issue in this issue backlog, and we believe this is important to fix for good "defense in depth" security practices - it's important to not expose any extra functionality that does not need to be exposed. Even if this current /uaa page returns an error if an attacker tries to input alternate configuration, it's still a serious potential vulnerability because another bug could come up that enabled them to submit real information and alter the system.
So we would encourage prioritizing this issue and considering any other place in Stratos where unnecessary functionality is exposed. Happy to provide further comments or ideas if helpful. Thank you!
/
The text was updated successfully, but these errors were encountered: