Feature #272
openFeature #235: [Security Audit Round 2 ]
[Security Audit Round 2 ] Improper Error Handling
0%
Description
Improper Error Handling
observation : New
CWE : CWE-388
Description :
Application discloses various error messages including stacktraces, exceptions, server
versions etc., in error messages.
Affected Path(s) :
/(Webserver)
Impact :
An adversary can use this information to construct further attacks.
Evidence/Proof Of Concept :
Step 1: Improper Error Handling as shown in below screenshot.
Step 2: Improper Error Handling as shown in below screenshot.
Files
Updated by Kalyan Battula 12 months ago
Kalyan Battula wrote:
Improper Error Handling
observation : New
CWE : CWE-388
Description :
Application discloses various error messages including stacktraces, exceptions, server
versions etc., in error messages.
Affected Path(s) :
/(Webserver)
Impact :
An adversary can use this information to construct further attacks.
Evidence/Proof Of Concept :
Step 1: Improper Error Handling as shown in below screenshot.Step 2: Improper Error Handling as shown in below screenshot.
Recommendation :
It is recommended to implement custom error pages and implement throughout the
application.
Updated by Harish Beechani 11 months ago
- Status changed from In Progress to Resolved
Updated by Harish Beechani 11 months ago
- Status changed from Resolved to Ready for Prod