devopsenggineer / Sanity

0 stars 0 forks source link

Vulnerability [ABAC_Level3] : GET:/v2/auth/aws/role/role #128

Open devopsenggineer opened 5 years ago

devopsenggineer commented 5 years ago

Project : t

Template : V2AuthAwsRoleRoleGetAwsauthloginuserbDisallowAbact3

Run Id : 8a8080b56a91f98d016a9b00d6cf3b04

Job : Default

Env : Default

Category : ABAC_Level3

Tags : [FX Top 10 - API Vulnerability, Data_Access_Control]

Severity : Major

Region : FXLabs/US_WEST_1

Result : fail

Status Code : 400

Headers : {Server=[nginx/1.12.1], Date=[Thu, 09 May 2019 05:11:32 GMT], Content-Type=[application/json;charset=ISO-8859-1], Content-Length=[49], Connection=[keep-alive]}

Endpoint : http://52.53.242.1/vault/v2/auth/aws/role/

Request :

Response :
{ "errors" : [ "Request method 'GET' not supported" ] }

Logs :
com.fxlabs.fxt.bot.assertions.AssertionLogger@7e550b8b --- FX Bot ---