Description
Improper authentication occurs when a system does not adequately establish a user's identity. An attacker may then access data or perform actions without authorization.
Potential impact
- Data disclosure: An attacker may read application data without authenticating.
- Privilege abuse or impersonation: An unauthorized user may obtain elevated privileges or act as another user.
- Unauthorized execution: If code or command execution functions are exposed, an unauthenticated user may abuse them.
Remediation
- Use a robust authentication mechanism to establish the identity of users or systems.
- Apply multi-factor authentication.
- Protect authentication data in storage and transit, for example by using HTTPS.
Examples
Before
java
@PostMapping("/login")
public String login(String username, String password, HttpSession session) {
if (username.equals("admin") && password.equals("admin")) {
session.setAttribute("user", "admin");
return "dashboard";
}
return "login";
}
After
java
@PostMapping("/login")
public String login(String username, String password, HttpSession session) {
User user = userService.authenticate(username, password);
if (user != null) {
session.setAttribute("user", user);
return "dashboard";
}
return "login";
}
Explanation:
- Before: Authentication relies on a fixed username and password that an attacker can use to bypass the intended identity check.
- After: An authentication service verifies the username and password. Merely moving the check into a separate method does not establish secure authentication; the service must implement password-hash verification and failure handling correctly.
Related CVEs
- CVE-2022-35248: A chat application's CAS configuration skips validation and removes the second authentication factor
- CVE-2022-36436: An authentication proxy accepts the 'None' authentication type without enforcing a password during the initial handshake
- CVE-2022-30034: Missing regex anchors in login-email validation (CWE-777) can allow OAuth bypass (CWE-1390) in a Python RPC framework's web UI