<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unauthenticated sensitive Information Disclosure - ArcGIS REST services in ArcGIS REST APIs and Services Questions</title>
    <link>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/unauthenticated-sensitive-information-disclosure/m-p/626256#M3050</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;Recently a security audit has been done on our servers and applications which has ArcGIS enterprise installed on it.&lt;/P&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;Our Architecture setup :&lt;/P&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;We have ArcGIS installed on the server, ArcGIS exposes its data via its restful api for its clients which is authenticated with OAuth2 token security (Out of the box ESRI Feature) We have mobile applications for both iOS/Android and web which are built on top of ESRI SDK’s.some of the features in the app consumes data from ArcGIS rest services for their functioning.&lt;/P&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;The audit reported a potential vulnerability stating that one of the rest service disclose sensitive informations including email and phone numbers even for non authenticated users.&lt;/P&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;consider web application, we make use of esri’s proxy files to manage access to our resources for them. the vulnerability is found for the following feature server query through the rest interface,&lt;/P&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;/webapp/proxy/proxy.ashx?&lt;A href="https://www.site.com/ArcGIS/rest/services/PublicPortal/xxxxxx/FeatureServer/0/query?f=json&amp;amp;where=EMAIL%20IS%20NOT%20NULL&amp;amp;returnGeometry=true&amp;amp;spatialRel=esriSpatialRelIntersects&amp;amp;outFields=" rel="nofollow noreferrer" style="color: rgba(53, 141, 170, 0.8); border: 0px; font-weight: inherit; text-decoration: underline;"&gt;https://www.site.com/ArcGIS/rest/services/PublicPortal/xxxxxx/FeatureServer/0/query?f=json&amp;amp;where=EMAIL%20IS%20NOT%20NULL&amp;amp;returnGeometry=true&amp;amp;spatialRel=esriSpatialRelIntersects&amp;amp;outFields=&lt;/A&gt;*&lt;/P&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;I understand this as a problem with the ArcGIS rest services, but I’m not sure about this, if some one could, please clarify the following points&lt;/P&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;1)what could be done to mitigate this problem.&lt;/P&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;Kindly please help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 Oct 2018 16:12:30 GMT</pubDate>
    <dc:creator>AsifIsmail</dc:creator>
    <dc:date>2018-10-30T16:12:30Z</dc:date>
    <item>
      <title>Unauthenticated sensitive Information Disclosure - ArcGIS REST services</title>
      <link>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/unauthenticated-sensitive-information-disclosure/m-p/626256#M3050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;Recently a security audit has been done on our servers and applications which has ArcGIS enterprise installed on it.&lt;/P&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;Our Architecture setup :&lt;/P&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;We have ArcGIS installed on the server, ArcGIS exposes its data via its restful api for its clients which is authenticated with OAuth2 token security (Out of the box ESRI Feature) We have mobile applications for both iOS/Android and web which are built on top of ESRI SDK’s.some of the features in the app consumes data from ArcGIS rest services for their functioning.&lt;/P&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;The audit reported a potential vulnerability stating that one of the rest service disclose sensitive informations including email and phone numbers even for non authenticated users.&lt;/P&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;consider web application, we make use of esri’s proxy files to manage access to our resources for them. the vulnerability is found for the following feature server query through the rest interface,&lt;/P&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;/webapp/proxy/proxy.ashx?&lt;A href="https://www.site.com/ArcGIS/rest/services/PublicPortal/xxxxxx/FeatureServer/0/query?f=json&amp;amp;where=EMAIL%20IS%20NOT%20NULL&amp;amp;returnGeometry=true&amp;amp;spatialRel=esriSpatialRelIntersects&amp;amp;outFields=" rel="nofollow noreferrer" style="color: rgba(53, 141, 170, 0.8); border: 0px; font-weight: inherit; text-decoration: underline;"&gt;https://www.site.com/ArcGIS/rest/services/PublicPortal/xxxxxx/FeatureServer/0/query?f=json&amp;amp;where=EMAIL%20IS%20NOT%20NULL&amp;amp;returnGeometry=true&amp;amp;spatialRel=esriSpatialRelIntersects&amp;amp;outFields=&lt;/A&gt;*&lt;/P&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;I understand this as a problem with the ArcGIS rest services, but I’m not sure about this, if some one could, please clarify the following points&lt;/P&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;1)what could be done to mitigate this problem.&lt;/P&gt;&lt;P style="color: #242729; background-color: #f9f8f6; border: 0px; margin: 0px 0px 1em;"&gt;Kindly please help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2018 16:12:30 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/unauthenticated-sensitive-information-disclosure/m-p/626256#M3050</guid>
      <dc:creator>AsifIsmail</dc:creator>
      <dc:date>2018-10-30T16:12:30Z</dc:date>
    </item>
  </channel>
</rss>

