freedomofpress / securedrop

GitHub repository for the SecureDrop whistleblower platform. Do not submit tips here!
https://securedrop.org/
Other
3.62k stars 688 forks source link

2024 Audit - SEC-01-004 WP4: Multiple Leaks via API Error Messages In Development Mode #7284

Closed zenmonkeykstop closed 2 days ago

zenmonkeykstop commented 2 days ago

Note: It was later found that this issue affects only deployments in developer mode, which is against the SecureDrop deployment guidelines. Error messages from the SecureDrop Source and Journalist APIs expose internal API information. A malicious attacker, in situations where the server is deployed in developer mode due to human error, could leverage this weakness to gain information about application internals, facilitating the exploitation of more significant vulnerabilities

Our developer environment intentionally reveals more information for debugging purposes. An administrator would have to go out of their way to put a production SecureDrop server into this state. We don’t plan to change this behavior.

zenmonkeykstop commented 2 days ago

Closing - looged for historical purposes only.