What Spring Data can teach us about API misconfiguration
ID: 7eb30107-cdd4-560a-aab7-85075a0ca898
STIX ID: report--7eb30107-cdd4-560a-aab7-85075a0ca898
Feed Name: TrustedSec blog
Threat Score
A researcher disclosed a critical misconfiguration in Spring Data REST's ALPS that lets unauthenticated clients fetch profile schemas (Accept: application/schema+json), enumerate user resources under /alps/users (with pageable size abuse to dump many records), and perform create/modify/delete operations without authorization; mitigations include implementing Spring Security pre-/post-authorization, using SpEL expressions, and disabling unsafe HTTP methods server-side.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
