Description
Exposing sensitive information to a user or system that has not been granted access is a security vulnerability.
Potential impact
An unauthorized user may obtain confidential data and use information about the system or its users.
Remediation
- Restrict access to sensitive information.
- Grant access only to users who need it, following least privilege.
- Encrypt sensitive data appropriately in storage and transit. Encryption does not replace application authorization checks.
- Filter sensitive values out of logs, including security logs.
Examples
These controller excerpts compare authentication and per-user authorization. getUserDetails() is a stub returning sample data; the real lookup is omitted. The server must authenticate the Principal, and its name must use the same user-identifier scheme as userId.
Before
java
@RestController
public class UserController {
@GetMapping("/user")
public String getUserInfo(@RequestParam String userId) {
// No per-user access check is shown.
return "Displaying user info: " + getUserDetails(userId);
}
private String getUserDetails(String userId) {
// User-information lookup stub
return "User Details"; // Simplified sample data
}
}
After
java
@RestController
public class UserController {
@GetMapping("/user")
public ResponseEntity<String> getUserInfo(@RequestParam String userId, Principal principal) {
// Require an authenticated principal matching the requested user.
if (principal == null || !principal.getName().equals(userId)) {
return new ResponseEntity<>("Access Denied", HttpStatus.FORBIDDEN);
}
return new ResponseEntity<>("Displaying user info: " + getUserDetails(userId), HttpStatus.OK);
}
private String getUserDetails(String userId) {
// User-information lookup stub
return "User Details"; // Simplified sample data
}
}
Explanation:
- Before: If the real lookup returns sensitive data and no separate authorization check applies, a requester can query another user’s ID.
- After: Rejects a missing principal or a requested ID that does not match the principal. This checks access to the user’s own information separately from authentication configuration. Also restrict the returned fields to what is needed.
Related CVEs
- CVE-2022-31162: Rust library leaks Oauth client details in application debug logs
- CVE-2021-25476: Digital Rights Management (DRM) capability for mobile platform leaks pointer information, simplifying ASLR bypass
- CVE-2001-1483: Enumeration of valid usernames based on inconsistent responses