jamf / JAWA

Jamf Automation and Webhook Assistant
MIT License
133 stars 12 forks source link

Security issue - Webhook authentication not supported by JAWA #14

Closed rtrouton closed 3 years ago

rtrouton commented 3 years ago

Webhooks created by JAWA do not use authentication when communicating to the JAWA server. This is a security risk, as those with the right URL can anonymously have the JAWA server perform the actions defined by that web hook.