Unauthenticated route returns non-sensitive PII data

Esta página aún no está disponible en español. Estamos trabajando en su traducción.
Si tienes alguna pregunta o comentario sobre nuestro actual proyecto de traducción, no dudes en ponerte en contacto con nosotros.

Description

The API allows unauthenticated users to access non-sensitive personally identifiable information (PII), which may not be intended.

What are considered non-sensitive personally identifiable information (PII)?

PII is information that can identify a user but, in isolation, could not cause significant harm to a person if leaked or stolen. This information includes full name, email address or phone numbers. Note: Datadog is only able to detect certain types of PII.

Rationale

This finding works by identifying an API that both:

Remediation

  • Validate that the code isn’t expecting the user to be authenticated to have access to this resource (AuthN). In case this API is in fact authenticated, ensure your code is instrumented correctly. Datadog auto-instruments many event types; review your instrumented business logic events.
  • Validate whether the API is intended to return PII.

References

ReferenceDescription
OWASP - Authentication Cheat SheetAuthentication Cheat Sheet: guidance on the best practices in the authentication area.