Base solution for your next web application
Open Closed

api/services/app/Session/GetCurrentLoginInformations leaks tenancy names #12239


User avatar
0
ITkcare created

What is your product version? 13.0.0

What is your product type (Angular or MVC)? Angular

What is product framework type (.net framework or .net core)? .net core


We found that the anonymous endpoint api/services/app/Session/GetCurrentLoginInformations will return tenancy names to an attacker after the value of Abp.TenantId is changed either by incrementing or guessing a number

Is that by design?
Any recommended action we take to limit the exposure?
Can the cookie be encrypted?

We are evaluating validating the endpoint to interrupt the request when the referer url does not contain the tenancy name the data store has associated to the Abp.TenantId header value That seem to prevent us from changing the tenant from the host site login screen but we could be ok as a remedy. Any concerns you may see with that?

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

6 Answer(s)
  • User Avatar
    0
    m.aliozkaya created
    Support Team

    Hi @ITkcare,

    I reproduced the problem. We can encrypt the cookies. I created an issue about it https://github.com/aspnetzero/aspnet-zero-core/issues/5470

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    ITkcare created

    Thanks, hoping to see that solved. Note our current Aspnetzero version is 13.0.0 updated the question above

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    ITkcare created

    Hi @ITkcare,

    I reproduced the problem. We can encrypt the cookies. I created an issue about it https://github.com/aspnetzero/aspnet-zero-core/issues/5470

    Will that issue take care of encrypting the Abp.TenantId header too or securing it? If it is changed as well the same Tenant name is leaked as well.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    ismcagdas created
    Support Team

    Hi @ITkcare

    We haven't worked on this yet. We might not use encryption for the solution by the way. Please follow related issue on GitHub to get updated.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    ITkcare created

    Hi @ITkcare

    We haven't worked on this yet. We might not use encryption for the solution by the way. Please follow related issue on GitHub to get updated.

    The github login code is never received so unable to check the link. Is there a way we can create users to delegate access?

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    oguzhanagir created
    Support Team

    Hi

    After logging in with the user who has the plan on the aspnetzero.com website, clicking the manage button under the Account button, you can give permission to the github user you are trying to log in from the Github Members tab on the relevant page.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)