Skip to content

security: OpenAPI spec (/api/openapi.json) declares all 689 endpoints as unauthenticated due to missing securitySchemes #34996

Description

@mbiuki

Summary

The OpenAPI specification served at /api/openapi.json declares "security": [] globally with no securitySchemes defined in components. This documents all 689 endpoints as requiring no authentication, even though the server code enforces auth on the vast majority of them.

Steps to Reproduce

  1. curl https://demo.dotcms.com/api/openapi.json | jq '.security, (.components.securitySchemes // "MISSING")'
  2. Observe: global security is [], securitySchemes is absent
  3. Run any automated security scanner (OWASP ZAP, 42Crunch) against the spec — all endpoints flagged as unauthenticated

Impact

  • Attacker reconnaissance: The full 689-endpoint attack surface appears open — reducing enumeration effort to zero
  • Developer misuse: Consumers of the spec may omit auth headers assuming endpoints are intentionally public
  • Security audit failures: Automated scanners generate false positives on every endpoint, burying real issues
  • Spec ≠ reality divergence: Erodes trust in API documentation as a security contract

Code Verification

All of the following resources properly enforce rejectWhenNoUser(true) in WebResource.InitBuilder — but the spec doesn't reflect this:

Resource Code Enforcement In Spec
MaintenanceResource rejectWhenNoUser(true) + admin + MAINTENANCE portlet No auth declared
RedisResource rejectWhenNoUser(true) + MAINTENANCE portlet No auth declared
SystemTableResource rejectWhenNoUser(true) + CMS_ADMINISTRATOR_ROLE No auth declared
ApiTokenResource rejectWhenNoUser(true) + users portlet No auth declared
UserResource rejectWhenNoUser(true) No auth declared
LicenseResource rejectWhenNoUser(true) + CONFIGURATION portlet No auth declared
OSGIResource rejectWhenNoUser(true) + DYNAMIC_PLUGINS portlet No auth declared
LoggerResource rejectWhenNoUser(true) + isAdmin() No auth declared
AppsResource rejectWhenNoUser(true) No auth declared
PermissionResource rejectWhenNoUser(true) + admin checks No auth declared

Root Cause

The openapi.json generator does not emit a securitySchemes block and JAX-RS resource methods lack @SecurityRequirement annotations.

Proposed Fix

  1. Add securitySchemes to components:
"securitySchemes": {
  "Bearer": { "type": "http", "scheme": "bearer", "bearerFormat": "JWT" },
  "BasicAuth": { "type": "http", "scheme": "basic" }
}
  1. Set a global default requiring auth:
"security": [{ "Bearer": [] }]
  1. Override with "security": [] at the operation level only for genuinely public endpoints (health checks, SAML metadata, login).

  2. Annotate JAX-RS resource methods with @SecurityRequirement so the spec stays accurate as new endpoints are added.

Acceptance Criteria

  • securitySchemes block present in components with Bearer JWT and BasicAuth schemes
  • Global security defaults to [{ "Bearer": [] }]
  • Genuinely public endpoints (health, auth, SAML metadata) explicitly declare security: []
  • Automated security scanner against the spec produces zero false-positive "unauthenticated endpoint" findings for admin/protected resources
  • @SecurityRequirement annotations added to all JAX-RS resource classes

Activity

  1. self-assigned this
    on Mar 16, 2026
  2. moved this from New to Next Sprint in dotCMS - Product Planningon Mar 16, 2026
  3. added a commit that references this issue on Mar 16, 2026
    063dbac
  4. github-actions commented on Mar 16, 2026

    @github-actions
    Contributor
  5. moved this from Next Sprint to In Review in dotCMS - Product Planningon Mar 16, 2026
  6. added
    CVSS : N/ANot a vulnerability: no CVSS v3.1 base score
    CVSS 4.0 : N/ACVSS 4.0: not a vulnerability
    and removed
    CVSS : N/ANot a vulnerability: no CVSS v3.1 base score
    on Sep 30, 2026
  7. mbiuki commented on Oct 7, 2026

    @mbiuki
    MemberAuthor

    Security assessment

    CVSS 4.0 N/A: The OpenAPI spec mislabels endpoints as unauthenticated, but the server still enforces auth, so nothing is exposed. This is a documentation and scanner-noise issue.
    Priority P4 · due 2027-03-16 (one year, 365 days from 2026-03-16) · project #7 (dotCMS - Product Planning): P4 - Low
    Weakness CWE-1059 Insufficient Technical Documentation · OWASP A05:2021 Security Misconfiguration

    Why this priority: The OpenAPI spec mislabels endpoints as unauthenticated, but the server still enforces auth, so nothing is exposed. This is a documentation and scanner-noise issue.

    Labels: already correct, no change.

    Automated triage by the dotCMS Security team (Claude), 2026-10-07. To override, change the project's Priority field or the CVSS label. The next refresh keeps a manual change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions