LCosta416140 (Community Member) asked a question.

how to fix or mitigate risks https://cwe.mitre.org/data/definitions/598.html ?

It was identified that the system passes information such as email and user IDs in the URL.

In this way, information can be logged in multiple locations including the user's browser, WAF server, backend server, and any proxy server that exists between the two points (client/server). URLs can also be displayed on screen, bookmarked or emailed by users. They can be written to third-party system logs via the Referer header when any external link is followed.

We use keyloack to pass authentication parameters in the URl. Please, how to pass these parameters from URL to body in the integration with Keycloak?


  • Hi @LCosta416140 (Community Member)​ ,

     

    None of Veracodes automated analyses report a flaw of this category. Was the the result of a Veracode Manual Penetration Test?

    I'm afraid we don't have any expertise in Keycloak, it might be best to reach out to members of their community: https://www.keycloak.org/community .

     

    Thank you,

    Boy Baukema

     

    Expand Post

Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.