Improper authentication

Improper Authentication

Description

Improper authentication occurs when a system does not adequately establish a user's identity. An attacker may then access data or perform actions without authorization.

Potential impact

  1. Data disclosure: An attacker may read application data without authenticating.
  2. Privilege abuse or impersonation: An unauthorized user may obtain elevated privileges or act as another user.
  3. Unauthorized execution: If code or command execution functions are exposed, an unauthenticated user may abuse them.

Remediation

  1. Use a robust authentication mechanism to establish the identity of users or systems.
  2. Apply multi-factor authentication.
  3. Protect authentication data in storage and transit, for example by using HTTPS.

Examples

Before

java
@PostMapping("/login")
public String login(String username, String password, HttpSession session) {
    if (username.equals("admin") && password.equals("admin")) {
        session.setAttribute("user", "admin");
        return "dashboard";
    }
    return "login";
}

After

java
@PostMapping("/login")
public String login(String username, String password, HttpSession session) {
    User user = userService.authenticate(username, password);
    if (user != null) {
        session.setAttribute("user", user);
        return "dashboard";
    }
    return "login";
}

Explanation:

  • Before: Authentication relies on a fixed username and password that an attacker can use to bypass the intended identity check.
  • After: An authentication service verifies the username and password. Merely moving the check into a separate method does not establish secure authentication; the service must implement password-hash verification and failure handling correctly.

Related CVEs

References