Petals Distribution

Support OWASP "Top 10 2013-A6-Sensitive Data Exposure"

Details

  • Type: Improvement Request Improvement Request
  • Status: New New
  • Priority: Major Major
  • Resolution: Unresolved
  • Affects Version/s: 4.3.0, 5.0.0-M1
  • Fix Version/s: None
  • Security Level: Public
  • Description:
    Hide

    All is in the title, and detailed here: https://www.owasp.org/index.php/Top_10_2013-A6-Sensitive_Data_Exposure.

    Impacts on Petals ESB are:

    • the local configuration file of a container (server.properties),
    • the topology definition (topology.xml),
    • the properties file of each JBI components,
    • some parameters use by sevice-units of each JBI components,
    • the Petals ESB CLI preferences file,
    • for Petals 5.x, we have also:
      • the local configuration file of a registry member (member.properties),
      • the registry cluster definition (cluster.xml),
      • the Petals Registry CLI preferences file.
    Show
    All is in the title, and detailed here: https://www.owasp.org/index.php/Top_10_2013-A6-Sensitive_Data_Exposure. Impacts on Petals ESB are:
    • the local configuration file of a container (server.properties),
    • the topology definition (topology.xml),
    • the properties file of each JBI components,
    • some parameters use by sevice-units of each JBI components,
    • the Petals ESB CLI preferences file,
    • for Petals 5.x, we have also:
      • the local configuration file of a registry member (member.properties),
      • the registry cluster definition (cluster.xml),
      • the Petals Registry CLI preferences file.
  • Environment:
    -

People

Dates

  • Created:
    Mon, 9 Nov 2015 - 16:31:39 +0100
    Updated:
    Mon, 9 Nov 2015 - 16:34:58 +0100