Public Access

Accessing data publicly




Is your data being publicly shared by your security rules? As you can see by actions of ACl above, despite good intentions, it did end up sharing sensitive data with external users.

A recent finding has identified a potential issue with simple list widget and ACL combination. If not set-up correctly, a lot of internal data could end up being shared with guest users. In case you haven't yet checked below excellent blog post, please do so at the earliest and take necessary actions.

https://www.enumerated.ie/index/servicenow-data-exposure.









Creative Commons License

Comments