-
Notifications
You must be signed in to change notification settings - Fork 21
Security Vulnerabilities in User Search API and File Upload #121
Copy link
Copy link
Open
sarpit2907/AnalySim
#1Description
While reviewing the project, I found the following security concerns:
1. Sensitive fields exposed in public search API
The search endpoint returns internal identity fields such as passwordHash, securityStamp, and concurrencyStamp.
Risk: Sensitive authentication data exposure.
Fix: Return a sanitized DTO with only public fields.
2. No file size limit on profile image upload
There is no maximum upload size enforced.
Risk: Possible DoS via large file uploads.
Fix: Add strict size limits and optionally rate limiting.
3. No validation of uploaded file type
No validation for file extension, MIME type, or file signature.
Risk: Malicious file upload (e.g., JS or executable files).
Fix: Enforce allow-list validation and verify file signatures.
I’d be happy to submit a PR addressing these issues if approved.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels