From 66f0ddeadf47022186f63d0afbc191714e6751ec Mon Sep 17 00:00:00 2001 From: fn20200323 <20200323@qwedc.eu.org> Date: Thu, 28 Oct 2021 21:05:41 +0200 Subject: [PATCH] Report roles verification for public ones --- README.md | 3 ++ ...check_1e7511642f2330100b40bea62799b6f1.xml | 38 +++++++++++++++++++ 2 files changed, 41 insertions(+) create mode 100644 scan_script_only_check_1e7511642f2330100b40bea62799b6f1.xml diff --git a/README.md b/README.md index b57a566..baf1a29 100644 --- a/README.md +++ b/README.md @@ -122,6 +122,9 @@ Monitor users with role `admin` (not locked out) that are not logged for longer After deactivation of Groups there can be still some users. Group offer membership but also can provide some roles that after deactivation should be considered as no longer needed. +### Report with public role can expose data to unauthenticated clients +For table that store reports definition there is also posibility to assign roles. It is possible that by default it is added `public` role. It means that even not authorized clients can access such report and sometimes with exposed data that shouldn't be accessible. + ## Category: User Experience diff --git a/scan_script_only_check_1e7511642f2330100b40bea62799b6f1.xml b/scan_script_only_check_1e7511642f2330100b40bea62799b6f1.xml new file mode 100644 index 0000000..e97918a --- /dev/null +++ b/scan_script_only_check_1e7511642f2330100b40bea62799b6f1.xml @@ -0,0 +1,38 @@ + + + +true +906611642f2330100b40bea62799b6b7 +security +It is worthy to check all reports that are with role public - as they can expose data to unauthenticated users via: + https : / / <instance>.service-now.com/sys_report_display.do?sysparm_report_id=<sysID> + +Public reports to be verified +2 + + +Candidates of publicly available reports (without needs to authorize) that shoul +scan_script_only_check +admin +2021-10-28 18:46:02 +1e7511642f2330100b40bea62799b6f1 +1 +Public reports to be verified +global + +global +scan_script_only_check_1e7511642f2330100b40bea62799b6f1 +admin +2021-10-28 18:50:32 + +