bcgov / bcgov/EDUC-SOAM-API

ZAP API Scan Report

Open
#104 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
4
Forks
3
PR merge metrics
No merged PRs in 30d

Description

- Site: [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca)
**New Alerts**
- **Spring Actuator Information Leak** [40042] total: 1:
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/actuator/health](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/actuator/health)
- **A Server Error response code was returned by the server** [100000] total: 7:
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/computeMetadata/v1/](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/computeMetadata/v1/)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/latest/meta-data/](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/latest/meta-data/)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/metadata/instance](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/metadata/instance)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/metadata/v1](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/metadata/v1)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/opc/v1/instance/](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/opc/v1/instance/)
- ..
- **Cookie with SameSite Attribute None** [10054] total: 5:
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/ssoGuid/sts-user-roles](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/ssoGuid/sts-user-roles)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/typeCode/typeValue](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/typeCode/typeValue)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/userInfo](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/userInfo)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/v3/api-docs](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/v3/api-docs)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/login](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/login)
- **Cross-Origin-Resource-Policy Header Missing or Invalid** [90004] total: 1:
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/v3/api-docs](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/v3/api-docs)
- **Unexpected Content-Type was returned** [100001] total: 7:
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/computeMetadata/v1/](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/computeMetadata/v1/)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/latest/meta-data/](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/latest/meta-data/)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/metadata/instance](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/metadata/instance)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/metadata/v1](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/metadata/v1)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/opc/v1/instance/](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/opc/v1/instance/)
- ..
- **A Client Error response code was returned by the server** [100000] total: 25:
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/7348888571887902685](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/7348888571887902685)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/ssoGuid](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/ssoGuid)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/ssoGuid/](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/ssoGuid/)
- ..
- **Non-Storable Content** [10049] total: 5:
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/ssoGuid/sts-user-roles](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/ssoGuid/sts-user-roles)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/typeCode/typeValue](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/typeCode/typeValue)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/v3/api-docs](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/v3/api-docs)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/link](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/link)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/login](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/login)
- **Session Management Response Identified** [10112] total: 7:
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/ssoGuid/sts-user-roles](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/ssoGuid/sts-user-roles)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/tenant?clientID=clientID&tenantID=tenantID](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/tenant?clientID=clientID&tenantID=tenantID)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/typeCode/typeValue](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/typeCode/typeValue)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/userInfo](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/userInfo)
- [https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/v3/api-docs](https://soam-api-75e61b-dev.apps.silver.devops.gov.bc.ca/v3/api-docs)
- ..

View the [following link](https://github.com/bcgov/EDUC-SOAM-API/actions/runs/28896106591) to download the report.
RunnerID:28896106591

---
[ZAP by Checkmarx](https://checkmarx.com/)

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the linked ZAP report and review each alert, especially the Spring Actuator health endpoint, API documentation, login and metadata paths. Confirm which findings are valid for this deployment and define the required remediation for each. Rerun the ZAP API scan and consider the work done when the actionable alerts are resolved or documented.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring-boot
Domain
api, backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.