devopsenggineer / Sanity

0 stars 0 forks source link

twre : ApiV1PrimaryTransactionGetRoleUserDisallowedRbac #13

Open devopsenggineer opened 5 years ago

devopsenggineer commented 5 years ago

Project : twre

Job : Default

Env : Default

Category : RBAC

Tags : [OWASP - OTG-IDENT-001 , FX Top 10 - API Vulnerability, Endpoint_Access_Control]

Severity : Major

Region : FXLabs/US_WEST_1

Result : fail

Status Code : 200

Headers : {X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Thu, 21 Feb 2019 09:59:23 GMT]}

Endpoint : http://54.215.136.217/api/v1/primary-transaction?pageSize=20

Request :

Response :
{ "requestId" : "None", "requestTime" : "2019-02-21T09:59:23.394+0000", "errors" : false, "messages" : [ ], "data" : [ { "id" : "216-88-8247", "createdBy" : "14", "createdDate" : "2019-02-13T05:53:24.564+0000", "modifiedBy" : "11", "modifiedDate" : "2019-02-13T23:25:01.777+0000", "version" : null, "inactive" : false, "description" : "Fairy tale", "type" : "Primary", "status" : "true", "amount" : 412458.0, "availableBalance" : 349857.0, "user" : null }, { "id" : "376-03-8720", "createdBy" : "11", "createdDate" : "2019-02-13T13:44:21.282+0000", "modifiedBy" : "14", "modifiedDate" : "2019-02-13T07:37:30.681+0000", "version" : null, "inactive" : false, "description" : "Classic", "type" : "Primary", "status" : "true", "amount" : 27611.0, "availableBalance" : 583679.0, "user" : null }, { "id" : "798-12-7821", "createdBy" : "11", "createdDate" : "2019-02-13T11:37:34.363+0000", "modifiedBy" : "11", "modifiedDate" : "2019-02-13T17:19:01.832+0000", "version" : null, "inactive" : false, "description" : "Fairy tale", "type" : "Primary", "status" : "false", "amount" : 122776.0, "availableBalance" : 451832.0, "user" : null }, { "id" : "707-11-0931", "createdBy" : "12", "createdDate" : "2019-02-13T01:17:52.718+0000", "modifiedBy" : "13", "modifiedDate" : "2019-02-13T11:42:06.953+0000", "version" : null, "inactive" : false, "description" : "Comic/Graphic Novel", "type" : "Primary", "status" : "true", "amount" : 565445.0, "availableBalance" : 554609.0, "user" : null }, { "id" : "171-90-2434", "createdBy" : "14", "createdDate" : "2019-02-13T13:29:29.878+0000", "modifiedBy" : "12", "modifiedDate" : "2019-02-13T14:42:16.914+0000", "version" : null, "inactive" : false, "description" : "Speech", "type" : "Primary", "status" : "true", "amount" : 483434.0, "availableBalance" : 502099.0, "user" : null }, { "id" : "858-70-8932", "createdBy" : "11", "createdDate" : "2019-02-13T04:08:49.153+0000", "modifiedBy" : "10", "modifiedDate" : "2019-02-13T01:10:45.998+0000", "version" : null, "inactive" : false, "description" : "Historical fiction", "type" : "Primary", "status" : "true", "amount" : 537046.0, "availableBalance" : 413070.0, "user" : null }, { "id" : "805-11-4231", "createdBy" : "12", "createdDate" : "2019-02-13T22:12:45.968+0000", "modifiedBy" : "11", "modifiedDate" : "2019-02-13T06:50:25.919+0000", "version" : null, "inactive" : false, "description" : "Fiction narrative", "type" : "Primary", "status" : "true", "amount" : 188423.0, "availableBalance" : 389741.0, "user" : null }, { "id" : "516-23-8543", "createdBy" : "14", "createdDate" : "2019-02-13T09:38:57.216+0000", "modifiedBy" : "10", "modifiedDate" : "2019-02-13T21:03:11.846+0000", "version" : null, "inactive" : false, "description" : "Realistic fiction", "type" : "Primary", "status" : "true", "amount" : 490401.0, "availableBalance" : 190713.0, "user" : null }, { "id" : "478-30-3228", "createdBy" : "12", "createdDate" : "2019-02-13T05:41:44.640+0000", "modifiedBy" : "12", "modifiedDate" : "2019-02-13T03:36:04.317+0000", "version" : null, "inactive" : false, "description" : "Textbook", "type" : "Primary", "status" : "true", "amount" : 521500.0, "availableBalance" : 235797.0, "user" : null }, { "id" : "638-71-0603", "createdBy" : "10", "createdDate" : "2019-02-13T14:47:50.639+0000", "modifiedBy" : "13", "modifiedDate" : "2019-02-13T11:16:35.897+0000", "version" : null, "inactive" : false, "description" : "Tall tale", "type" : "Primary", "status" : "false", "amount" : 454216.0, "availableBalance" : 138564.0, "user" : null }, { "id" : "280-64-7066", "createdBy" : "10", "createdDate" : "2019-02-13T21:11:49.311+0000", "modifiedBy" : "14", "modifiedDate" : "2019-02-13T06:39:34.463+0000", "version" : null, "inactive" : false, "description" : "Textbook", "type" : "Primary", "status" : "false", "amount" : 194231.0, "availableBalance" : 454793.0, "user" : null }, { "id" : "639-96-0917", "createdBy" : "12", "createdDate" : "2019-02-13T12:33:28.972+0000", "modifiedBy" : "12", "modifiedDate" : "2019-02-13T11:56:40.034+0000", "version" : null, "inactive" : false, "description" : "Classic", "type" : "Primary", "status" : "true", "amount" : 583168.0, "availableBalance" : 14973.0, "user" : null }, { "id" : "527-55-3975", "createdBy" : "14", "createdDate" : "2019-02-13T22:39:42.065+0000", "modifiedBy" : "11", "modifiedDate" : "2019-02-13T14:54:49.130+0000", "version" : null, "inactive" : false, "description" : "Western", "type" : "Primary", "status" : "true", "amount" : 150089.0, "availableBalance" : 494977.0, "user" : null }, { "id" : "816-46-9799", "createdBy" : "11", "createdDate" : "2019-02-13T20:23:46.474+0000", "modifiedBy" : "12", "modifiedDate" : "2019-02-13T18:23:07.103+0000", "version" : null, "inactive" : false, "description" : "Fantasy", "type" : "Primary", "status" : "false", "amount" : 567399.0, "availableBalance" : 175335.0, "user" : null }, { "id" : "667-95-9714", "createdBy" : "14", "createdDate" : "2019-02-13T21:57:45.217+0000", "modifiedBy" : "14", "modifiedDate" : "2019-02-13T13:53:35.118+0000", "version" : null, "inactive" : false, "description" : "Mystery", "type" : "Primary", "status" : "true", "amount" : 8108.0, "availableBalance" : 80202.0, "user" : null }, { "id" : "668-60-2451", "createdBy" : "12", "createdDate" : "2019-02-13T06:12:16.838+0000", "modifiedBy" : "14", "modifiedDate" : "2019-02-13T09:29:45.869+0000", "version" : null, "inactive" : false, "description" : "Humor", "type" : "Primary", "status" : "false", "amount" : 391254.0, "availableBalance" : 571066.0, "user" : null }, { "id" : "567-14-8294", "createdBy" : "13", "createdDate" : "2019-02-13T01:30:17.715+0000", "modifiedBy" : "10", "modifiedDate" : "2019-02-13T14:51:50.349+0000", "version" : null, "inactive" : false, "description" : "Horror", "type" : "Primary", "status" : "true", "amount" : 488204.0, "availableBalance" : 435576.0, "user" : null }, { "id" : "278-71-2898", "createdBy" : "10", "createdDate" : "2019-02-13T08:06:37.678+0000", "modifiedBy" : "12", "modifiedDate" : "2019-02-13T02:11:19.084+0000", "version" : null, "inactive" : false, "description" : "Reference book", "type" : "Primary", "status" : "false", "amount" : 561510.0, "availableBalance" : 519569.0, "user" : null }, { "id" : "806-11-5570", "createdBy" : "13", "createdDate" : "2019-02-13T10:25:17.821+0000", "modifiedBy" : "11", "modifiedDate" : "2019-02-13T23:04:37.435+0000", "version" : null, "inactive" : false, "description" : "Legend", "type" : "Primary", "status" : "false", "amount" : 500258.0, "availableBalance" : 343252.0, "user" : null }, { "id" : "745-42-5113", "createdBy" : "13", "createdDate" : "2019-02-13T08:31:47.392+0000", "modifiedBy" : "11", "modifiedDate" : "2019-02-13T21:03:45.507+0000", "version" : null, "inactive" : false, "description" : "Textbook", "type" : "Primary", "status" : "false", "amount" : 428540.0, "availableBalance" : 264096.0, "user" : null } ], "totalPages" : 0, "totalElements" : 0 }

Logs :
2019-02-21 09:59:23 DEBUG [ApiV1PrimaryTransactionGetRoleUserDisallowedRbac] : URL [http://54.215.136.217/api/v1/primary-transaction?pageSize=20] 2019-02-21 09:59:23 DEBUG [ApiV1PrimaryTransactionGetRoleUserDisallowedRbac] : Method [GET] 2019-02-21 09:59:23 DEBUG [ApiV1PrimaryTransactionGetRoleUserDisallowedRbac] : Request [] 2019-02-21 09:59:23 DEBUG [ApiV1PrimaryTransactionGetRoleUserDisallowedRbac] : Request-Headers [{Content-Type=[application/json], Accept=[application/json]}] 2019-02-21 09:59:23 DEBUG [ApiV1PrimaryTransactionGetRoleUserDisallowedRbac] : Response [{ "requestId" : "None", "requestTime" : "2019-02-21T09:59:23.394+0000", "errors" : false, "messages" : [ ], "data" : [ { "id" : "216-88-8247", "createdBy" : "14", "createdDate" : "2019-02-13T05:53:24.564+0000", "modifiedBy" : "11", "modifiedDate" : "2019-02-13T23:25:01.777+0000", "version" : null, "inactive" : false, "description" : "Fairy tale", "type" : "Primary", "status" : "true", "amount" : 412458.0, "availableBalance" : 349857.0, "user" : null }, { "id" : "376-03-8720", "createdBy" : "11", "createdDate" : "2019-02-13T13:44:21.282+0000", "modifiedBy" : "14", "modifiedDate" : "2019-02-13T07:37:30.681+0000", "version" : null, "inactive" : false, "description" : "Classic", "type" : "Primary", "status" : "true", "amount" : 27611.0, "availableBalance" : 583679.0, "user" : null }, { "id" : "798-12-7821", "createdBy" : "11", "createdDate" : "2019-02-13T11:37:34.363+0000", "modifiedBy" : "11", "modifiedDate" : "2019-02-13T17:19:01.832+0000", "version" : null, "inactive" : false, "description" : "Fairy tale", "type" : "Primary", "status" : "false", "amount" : 122776.0, "availableBalance" : 451832.0, "user" : null }, { "id" : "707-11-0931", "createdBy" : "12", "createdDate" : "2019-02-13T01:17:52.718+0000", "modifiedBy" : "13", "modifiedDate" : "2019-02-13T11:42:06.953+0000", "version" : null, "inactive" : false, "description" : "Comic/Graphic Novel", "type" : "Primary", "status" : "true", "amount" : 565445.0, "availableBalance" : 554609.0, "user" : null }, { "id" : "171-90-2434", "createdBy" : "14", "createdDate" : "2019-02-13T13:29:29.878+0000", "modifiedBy" : "12", "modifiedDate" : "2019-02-13T14:42:16.914+0000", "version" : null, "inactive" : false, "description" : "Speech", "type" : "Primary", "status" : "true", "amount" : 483434.0, "availableBalance" : 502099.0, "user" : null }, { "id" : "858-70-8932", "createdBy" : "11", "createdDate" : "2019-02-13T04:08:49.153+0000", "modifiedBy" : "10", "modifiedDate" : "2019-02-13T01:10:45.998+0000", "version" : null, "inactive" : false, "description" : "Historical fiction", "type" : "Primary", "status" : "true", "amount" : 537046.0, "availableBalance" : 413070.0, "user" : null }, { "id" : "805-11-4231", "createdBy" : "12", "createdDate" : "2019-02-13T22:12:45.968+0000", "modifiedBy" : "11", "modifiedDate" : "2019-02-13T06:50:25.919+0000", "version" : null, "inactive" : false, "description" : "Fiction narrative", "type" : "Primary", "status" : "true", "amount" : 188423.0, "availableBalance" : 389741.0, "user" : null }, { "id" : "516-23-8543", "createdBy" : "14", "createdDate" : "2019-02-13T09:38:57.216+0000", "modifiedBy" : "10", "modifiedDate" : "2019-02-13T21:03:11.846+0000", "version" : null, "inactive" : false, "description" : "Realistic fiction", "type" : "Primary", "status" : "true", "amount" : 490401.0, "availableBalance" : 190713.0, "user" : null }, { "id" : "478-30-3228", "createdBy" : "12", "createdDate" : "2019-02-13T05:41:44.640+0000", "modifiedBy" : "12", "modifiedDate" : "2019-02-13T03:36:04.317+0000", "version" : null, "inactive" : false, "description" : "Textbook", "type" : "Primary", "status" : "true", "amount" : 521500.0, "availableBalance" : 235797.0, "user" : null }, { "id" : "638-71-0603", "createdBy" : "10", "createdDate" : "2019-02-13T14:47:50.639+0000", "modifiedBy" : "13", "modifiedDate" : "2019-02-13T11:16:35.897+0000", "version" : null, "inactive" : false, "description" : "Tall tale", "type" : "Primary", "status" : "false", "amount" : 454216.0, "availableBalance" : 138564.0, "user" : null }, { "id" : "280-64-7066", "createdBy" : "10", "createdDate" : "2019-02-13T21:11:49.311+0000", "modifiedBy" : "14", "modifiedDate" : "2019-02-13T06:39:34.463+0000", "version" : null, "inactive" : false, "description" : "Textbook", "type" : "Primary", "status" : "false", "amount" : 194231.0, "availableBalance" : 454793.0, "user" : null }, { "id" : "639-96-0917", "createdBy" : "12", "createdDate" : "2019-02-13T12:33:28.972+0000", "modifiedBy" : "12", "modifiedDate" : "2019-02-13T11:56:40.034+0000", "version" : null, "inactive" : false, "description" : "Classic", "type" : "Primary", "status" : "true", "amount" : 583168.0, "availableBalance" : 14973.0, "user" : null }, { "id" : "527-55-3975", "createdBy" : "14", "createdDate" : "2019-02-13T22:39:42.065+0000", "modifiedBy" : "11", "modifiedDate" : "2019-02-13T14:54:49.130+0000", "version" : null, "inactive" : false, "description" : "Western", "type" : "Primary", "status" : "true", "amount" : 150089.0, "availableBalance" : 494977.0, "user" : null }, { "id" : "816-46-9799", "createdBy" : "11", "createdDate" : "2019-02-13T20:23:46.474+0000", "modifiedBy" : "12", "modifiedDate" : "2019-02-13T18:23:07.103+0000", "version" : null, "inactive" : false, "description" : "Fantasy", "type" : "Primary", "status" : "false", "amount" : 567399.0, "availableBalance" : 175335.0, "user" : null }, { "id" : "667-95-9714", "createdBy" : "14", "createdDate" : "2019-02-13T21:57:45.217+0000", "modifiedBy" : "14", "modifiedDate" : "2019-02-13T13:53:35.118+0000", "version" : null, "inactive" : false, "description" : "Mystery", "type" : "Primary", "status" : "true", "amount" : 8108.0, "availableBalance" : 80202.0, "user" : null }, { "id" : "668-60-2451", "createdBy" : "12", "createdDate" : "2019-02-13T06:12:16.838+0000", "modifiedBy" : "14", "modifiedDate" : "2019-02-13T09:29:45.869+0000", "version" : null, "inactive" : false, "description" : "Humor", "type" : "Primary", "status" : "false", "amount" : 391254.0, "availableBalance" : 571066.0, "user" : null }, { "id" : "567-14-8294", "createdBy" : "13", "createdDate" : "2019-02-13T01:30:17.715+0000", "modifiedBy" : "10", "modifiedDate" : "2019-02-13T14:51:50.349+0000", "version" : null, "inactive" : false, "description" : "Horror", "type" : "Primary", "status" : "true", "amount" : 488204.0, "availableBalance" : 435576.0, "user" : null }, { "id" : "278-71-2898", "createdBy" : "10", "createdDate" : "2019-02-13T08:06:37.678+0000", "modifiedBy" : "12", "modifiedDate" : "2019-02-13T02:11:19.084+0000", "version" : null, "inactive" : false, "description" : "Reference book", "type" : "Primary", "status" : "false", "amount" : 561510.0, "availableBalance" : 519569.0, "user" : null }, { "id" : "806-11-5570", "createdBy" : "13", "createdDate" : "2019-02-13T10:25:17.821+0000", "modifiedBy" : "11", "modifiedDate" : "2019-02-13T23:04:37.435+0000", "version" : null, "inactive" : false, "description" : "Legend", "type" : "Primary", "status" : "false", "amount" : 500258.0, "availableBalance" : 343252.0, "user" : null }, { "id" : "745-42-5113", "createdBy" : "13", "createdDate" : "2019-02-13T08:31:47.392+0000", "modifiedBy" : "11", "modifiedDate" : "2019-02-13T21:03:45.507+0000", "version" : null, "inactive" : false, "description" : "Textbook", "type" : "Primary", "status" : "false", "amount" : 428540.0, "availableBalance" : 264096.0, "user" : null } ], "totalPages" : 0, "totalElements" : 0 }] 2019-02-21 09:59:23 DEBUG [ApiV1PrimaryTransactionGetRoleUserDisallowedRbac] : Response-Headers [{X-Content-Type-Options=[nosniff], X-XSS-Protection=[1; mode=block], Cache-Control=[no-cache, no-store, max-age=0, must-revalidate], Pragma=[no-cache], Expires=[0], X-Frame-Options=[DENY], Content-Type=[application/json;charset=UTF-8], Transfer-Encoding=[chunked], Date=[Thu, 21 Feb 2019 09:59:23 GMT]}] 2019-02-21 09:59:23 DEBUG [ApiV1PrimaryTransactionGetRoleUserDisallowedRbac] : StatusCode [200] 2019-02-21 09:59:23 DEBUG [ApiV1PrimaryTransactionGetRoleUserDisallowedRbac] : Time [23] 2019-02-21 09:59:23 DEBUG [ApiV1PrimaryTransactionGetRoleUserDisallowedRbac] : Size [6075] 2019-02-21 09:59:23 ERROR [ApiV1PrimaryTransactionGetRoleUserDisallowedRbac] : Assertion [@StatusCode == 401 OR @StatusCode == 403] resolved-to [200 == 401 OR 200 == 403] result [Failed]

--- FX Bot ---