-
Notifications
You must be signed in to change notification settings - Fork 236
[BUG] Missing Rate Limiters on Management Endpoints #1488
Copy link
Copy link
Closed
Labels
area:backendBackend API, database, or service workBackend API, database, or service workarea:securitySecurity-sensitive implementation or testsSecurity-sensitive implementation or testslevel:advanced55 pts difficulty label for advanced contributor PRs55 pts difficulty label for advanced contributor PRspriority:highHigh-priority issueHigh-priority issuetype:bugBug fix work category bonus labelBug fix work category bonus labeltype:securitySecurity work category bonus labelSecurity work category bonus label
Description
Activity
Metadata
Metadata
Assignees
Labels
area:backendBackend API, database, or service workBackend API, database, or service workarea:securitySecurity-sensitive implementation or testsSecurity-sensitive implementation or testslevel:advanced55 pts difficulty label for advanced contributor PRs55 pts difficulty label for advanced contributor PRspriority:highHigh-priority issueHigh-priority issuetype:bugBug fix work category bonus labelBug fix work category bonus labeltype:securitySecurity work category bonus labelSecurity work category bonus label
Missing Rate Limiters on Management Endpoints
Description:
Several administrative and management endpoints lack rate limiting protections, leaving them vulnerable to Denial of Service (DoS) attacks through database spamming or resource exhaustion.
Affected Endpoints (backend/secuscan/routes.py):
@router.delete("/tasks/bulk")@router.delete("/tasks/clear")@router.post("/target-policies"),@router.patch("/target-policies/{policy_id}"),@router.delete("/target-policies/{policy_id}")@router.post("/credential-profiles"),@router.patch(...),@router.delete(...)@router.post("/session-profiles"),@router.patch(...),@router.delete(...)@router.get("/plugins"),@router.get("/presets")@router.post("/workflows"),@router.patch("/workflows/{workflow_id}")Recommendation:
Apply an appropriate rate limiter (such as
admin_limiterorread_heavy_limiter) viaDepends(...)to all management endpoints to prevent abuse.