What is your product version? 13.0.0
What is your product type (Angular or MVC)? Angular
What is product framework type (.net framework or .net core)? .net core
We found that the anonymous endpoint api/services/app/Session/GetCurrentLoginInformations will return tenancy names to an attacker after the value of Abp.TenantId is changed either by incrementing or guessing a number
Is that by design?
Any recommended action we take to limit the exposure?
Can the cookie be encrypted?
We are evaluating validating the endpoint to interrupt the request when the referer url does not contain the tenancy name the data store has associated to the Abp.TenantId header value That seem to prevent us from changing the tenant from the host site login screen but we could be ok as a remedy. Any concerns you may see with that?
6 Answer(s)
-
0
Hi @ITkcare,
I reproduced the problem. We can encrypt the cookies. I created an issue about it https://github.com/aspnetzero/aspnet-zero-core/issues/5470
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Thanks, hoping to see that solved. Note our current Aspnetzero version is 13.0.0 updated the question above
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @ITkcare,
I reproduced the problem. We can encrypt the cookies. I created an issue about it https://github.com/aspnetzero/aspnet-zero-core/issues/5470
Will that issue take care of encrypting the Abp.TenantId header too or securing it? If it is changed as well the same Tenant name is leaked as well.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @ITkcare
We haven't worked on this yet. We might not use encryption for the solution by the way. Please follow related issue on GitHub to get updated.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi @ITkcare
We haven't worked on this yet. We might not use encryption for the solution by the way. Please follow related issue on GitHub to get updated.
The github login code is never received so unable to check the link. Is there a way we can create users to delegate access?
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image) -
0
Hi
After logging in with the user who has the plan on the aspnetzero.com website, clicking the manage button under the Account button, you can give permission to the github user you are trying to log in from the Github Members tab on the relevant page.
Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image)