HubSpot Ideas

DivyaSharmaDixt

The application responds with verbose error messages when malicious parameters are sent in the input

The error message contains extracts from stack trace of JSON parser. This can be used to build more advanced threat vectors. It is also among the top 10 OWASP vulnerabilities. As a secure practice, it is never advised to issue verbose errors or stack traces to frontend. We follow OWASP and SANS standards across the org. Although this is not a huge risk, it needs to be fixed.

0 Upvotes