Excessive Data Exposure

Excessive data exposure in C#

Description

Excessive data exposure occurs when an API response includes sensitive information that the endpoint does not need or the caller is not authorized to receive. This can involve password hashes, API keys, access tokens, private keys, national identification numbers or SSNs, payment card details, bank accounts, or medical information.

Potential impact

  • Sensitive information may leak through response recipients or intermediary logging systems.
  • Combined with other vulnerabilities, the exposure may lead to account takeover, compromised payment information, or privacy violations.

Remediation

Use response DTOs to return only fields needed by the endpoint and authorized for the caller, rather than entire entities. Exclude secrets such as password hashes and private keys from ordinary client responses. Remove tokens, payment information, and internal notes when they are unnecessary for that function or unauthorized for the caller.

Examples

Before

csharp
return Ok(new
{
    username = "alice",
    password = "hashed_password",
    ssn = "123-45-6789"
});

After

csharp
return Ok(new
{
    username = "alice",
    email = "alice@example.com"
});

Explanation:

  • Before: This response includes a password hash and SSN that the client does not need.
  • After: Return only fields needed for this function and authorized for the caller. Include government identifiers, payment data, or internal notes only when their purpose and access permissions justify doing so.

References