REST API calls that should be blocked are allowed
-
I noticed a couple of REST API calls that I think should have been blocked but that were passed by Cerber. In the hardening settings all namespaces except 1 are blocked but still I see some REST calls from not-logged-in users being passed also to other namespaces. Most calls are blocked as should, but these spurious misses are a bit worrisome, especially as user enumeration seems to have been at least one of the cases.
Running the latest version of Cerber (8.9.5).
Here are a couple of slips: screenshot 1
Here are my current settings: screenshot 2
Viewing 6 replies - 1 through 6 (of 6 total)
Viewing 6 replies - 1 through 6 (of 6 total)
- The topic ‘REST API calls that should be blocked are allowed’ is closed to new replies.