SAP / spartacus

Spartacus is a lean, Angular-based JavaScript storefront for SAP Commerce Cloud that communicates exclusively through the Commerce REST API.
Apache License 2.0
744 stars 389 forks source link

Client-side HTTP Parameter Pollution (Reflected) #10107

Open giancorderoortiz opened 3 years ago

giancorderoortiz commented 3 years ago

https://github.tools.sap/cx-commerce/spasec/issues/49

Found with 3.0 RC1

giancorderoortiz commented 3 years ago

Please refrain from closing this ticket until assessment from architect and internal security expert has been given.

Xymmer commented 3 years ago

Not showstopper but let's investigated in the future We're not sure if related to Spartacus

hackergil commented 3 years ago

@giancorderoortiz I went to look at the description and it's not clear. Would you mind adding a better one? Also, if you want an assessment from architect and internal security team, who should we assign this to?