DefaultGetServlet leads to access of AEM nodes | Community
Skip to main content
August 10, 2022
Solved

DefaultGetServlet leads to access of AEM nodes

  • August 10, 2022
  • 1 reply
  • 1021 views

Hi 

 

While checking for the application security, we have found that the POST Servlet is exposed, which allows to anonymous user to add jcr:node

POST /.json;%0AKPI.css HTTP/2
Host: <domain>
User-Agent: curl/7.30.0
Accept-Encoding: gzip, deflate
Accept: /
Content-Type: application/x-www-form-urlencoded
Referer: <doamin>
Content-Length: 14

:operation=nop


we have just use NOP operation to prove it’s exposed ,attacker can use any other operation here

 

What's the best possible way to restrict it without impact the running application?

 

Thanks,

Rajendra

This post is no longer active and is closed to new replies. Need help? Start a new post to ask your question.
Best answer by Nikhil_Verma

Add below to your dispatcher filter rules:

 

1 reply

Nikhil_Verma
Nikhil_VermaAccepted solution
Level 4
August 12, 2022

Add below to your dispatcher filter rules: