Cross-tenant URL signing

Steps to reproduce

Both the URL Singing REST Endpoint and the External API - Security Endpoint can be used by authorized users to sign URLs.
Since signing keys do not belong to specific organizations (tenants), any authorized user can indirectly use any signing key.

With other words: An authorized user of organization A can sign URLs of organization B that allows organization A to access distribution artefacts of organization B.

Assignee

Sven Stauber

Reporter

Sven Stauber

Severity

Security

Tags (folksonomy)

None

Components

Fix versions

Affects versions

Priority

Critical
Configure