Replies: 1 comment
-
The API being opened, the automation of POST submission is a feature of udata open data platform, used by many data producers. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
The application data.gouv.fr provides forms that are not protected against automation of submissions on the pages:
Note: Although authentication is required, any user can create an account (with administrative access by default) and create these requests.
In this way, an attacker could degrade the service, as they would overload the server with a large amount of element creation. Furthermore, these submissions create entries on the page with public access.
Suggestion:
Implementation of a control against automation of form submission, for example, (if applicable) through the implementation of a CAPTCHA system (Completely Automated Public Turing test to tell Computers and Humans Apart), or limiting the submission speed (rate- limiting).
Beta Was this translation helpful? Give feedback.
All reactions