Security Checklist
Overview
This checklist helps you assess the security of your Bloomreach Content implementation. It aligns with the OWASP Top 10 security risks and highlights both platform-level protections and areas requiring implementation-level verification.
The checklist distinguishes between protections provided by Bloomreach Content ([✓]) and items that require action or verification in your implementation ([ ! ]). This list is not exhaustive. Always perform a comprehensive security audit before deploying your solution.
If you identify a security vulnerability in a Bloomreach product, do not create a JIRA issue. Instead, follow the Security Issues Procedure.
OWASP Top 10 Security Risks
Reference: https://www.owasp.org/index.php/Top_10_2013-Top_10
A1 - Injection
Authoring
- [✓] Bloomreach Content provides CRLF Injection prevention at the application level.
- [✓] HTML rich text content entered through the CMS is filtered using HTML cleaning.
Delivery
- [ ! ] Ensure that all templates only render filtered or encoded user input, including CMS content.
- [ ! ] Sanitize all user-submitted search parameters before using them in repository queries.
- [ ! ] Confirm that your application container prevents CRLF injection. Tomcat 8, the default container, includes this protection.
A2 - Broken Authentication and Session Management
Authoring
- [ ! ] Protect against session fixation. In Tomcat, set the session tracking mode to COOKIE.
- [ ! ] Disable login form auto-completion if required.
Delivery
- [ ! ] For user authentication, use provided and properly configured authentication mechanisms.
- [ ! ] If using the Relevance Module, set the visitor cookie to include the HttpOnly flag (brXM 12.0.1+).
A3 - Cross-Site Scripting (XSS)
Authoring
- [✓] Bloomreach Content includes built-in protection against XSS.
Delivery
- [ ! ] In your
siteweb application, configure the XSSUrlFilter as the first filter in theweb.xmlexecution chain.
A4 - Insecure Direct Object References
Authoring
- [✓] Access to content objects requires authentication and authorization.
Delivery
- [ ! ] Do not expose JCR identifiers (UUIDs) in URLs or other outputs in your delivery tier implementation.
A5 - Security Misconfiguration
Authoring
- [ ! ] Configure password validation and expiration.
- [ ! ] Create appropriate users and groups and assign correct permissions.
- [ ! ] Remove or change passwords for default users (author, editor, admin).
- [ ! ] Enable audit logging.
- [ ! ] Restrict Console access to administrators.
- [ ! ] Optionally, enable two-factor authentication.
- [ ! ] Optionally, enable LDAP authentication.
- [ ! ] Optionally, enable SSO integration.
Delivery
- [ ! ] Configure delivery tier users and assign appropriate privileges.
A6 - Sensitive Data Exposure
Authoring
- [ ! ] Optionally, add the Embargo Plugin.
Delivery
- [ ! ] Ensure the HST allowlist excludes web files that should not be public, such as Freemarker templates.
- [ ! ] Use HTTPS for all authenticated pages.
- [ ! ] Comply with privacy and data protection laws. Encrypt all personal user data.
A7 - Missing Function Level Access Control
Authoring
- [✓] Bloomreach Content provides publication workflow by default.
Delivery
- [ ! ] Perform all write operations in the delivery tier using a Persistable Session from the API to ensure correct credentials and privileges.
- [ ! ] Use the ContentNodeBinder interface and WorkflowPersistanceManager service for all workflow operations in the delivery tier.
A8 - Cross-Site Request Forgery (CSRF)
Authoring
- [✓] Bloomreach Content prevents CSRF by validating the Origin HTTP header.
Delivery
- [ ! ] Add CSRF protection to all state-changing links and forms.
A9 - Using Components with Known Vulnerabilities
Authoring and Delivery
- [ ! ] Use the Bloomreach Content Release POM as the parent in your Maven project.
- [ ! ] Use the latest Bloomreach Content release.
- [ ! ] Keep all Maven dependencies up-to-date and free of known vulnerabilities.
- [ ! ] Keep all JavaScript libraries up-to-date and free of known vulnerabilities.
A10 - Unvalidated Redirects and Forwards
Authoring
- [ ! ] If using the URL Rewriter Plugin, only allow trusted users to create, modify, or publish URL rewrite rules.
Delivery
- [ ! ] Do not implement redirects or forwards to destinations based on unverified user-submitted parameters.