This repository has been archived by the owner on Oct 21, 2022. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 0
Issues: edubadges/audit
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
Enumeration of registered email addresses via user profile API
bug-infoleak
risk-moderate
Security issues with a moderate impact
Timing-side channel in API helps testing if an email address is registered
bug-infoleak
risk-moderate
Security issues with a moderate impact
Upload files with arbitrary extensions to publicly accessible URL
bug-file-upload
risk-high
Security issues with a high impact
Hardcoded Unsubscribe token in settings.py
bug-infoleak
risk-moderate
Security issues with a moderate impact
Use any e-mail-address as the issuers address.
bug-functionality
Abuse of functionality
risk-low
Security issues with a low impact
#24
opened Jun 18, 2018 by
sveeke
Frameable response (potential Clickjacking)
bug-infrastructure
Bugs inside SURFnet's infrastructure
risk-moderate
Security issues with a moderate impact
SSL Medium and RC4 Ciphers supported
bug-infrastructure
Bugs inside SURFnet's infrastructure
risk-moderate
Security issues with a moderate impact
SSH Server Publicly Accessible
bug-infrastructure
Bugs inside SURFnet's infrastructure
risk-low
Security issues with a low impact
No rate limiting on resend verification mail.
bug-security
risk-moderate
Security issues with a moderate impact
Improve Input Validation and output Sanitization.
bug-security
risk-low
Security issues with a low impact
Cipher Order Determined by Client
bug-infrastructure
Bugs inside SURFnet's infrastructure
risk-low
Security issues with a low impact
Web Browser XSS Protection Not Enabled
bug-infrastructure
Bugs inside SURFnet's infrastructure
risk-low
Security issues with a low impact
The provider parameter does not use the proper error control
bug-infoleak
risk-low
Security issues with a low impact
User Enumeration using the issuer manage staff functionality
bug-infoleak
risk-low
Security issues with a low impact
The "name" parameter of the award a badge functionality lacks any input validation
bug-security
risk-low
Security issues with a low impact
No Bruteforce Protection on Account Login
bug-security
risk-moderate
Security issues with a moderate impact
Missing HTTP Strict-Transport-Security Headers
bug-infrastructure
Bugs inside SURFnet's infrastructure
risk-low
Security issues with a low impact
SSH Server on surf-dev2.edubadges.nl has CBC Mode Ciphers Enabled
bug-infrastructure
Bugs inside SURFnet's infrastructure
risk-low
Security issues with a low impact
ProTip!
Updated in the last three days: updated:>2025-01-01.