Description
Incorrect assignment, modification, tracking, or review of privileges can allow access or actions beyond what is needed.
Potential impact
- An attacker may gain excessive privileges, perform unauthorized actions, or act as another user.
Remediation
- Follow least privilege: grant users and processes only the permissions they need.
- Manage permissions through role-based access control (RBAC).
- Log privilege changes and review them regularly.
- Require an established approval process for privilege changes.
These examples assume method security is enabled, for example with @EnableMethodSecurity, and calls pass through the security proxy of a Spring-managed bean.
Examples
Before
java
@PreAuthorize("hasRole('USER')")
public void performAdminTask() {
// Perform the administrative operation
}
After
java
@PreAuthorize("hasRole('ADMIN')")
public void performAdminTask() {
// Perform the administrative operation
}
Explanation:
- Before: The
USERrole is sufficient to run an administrative operation. - After: Access to this method requires the
ADMINrole. Assign that role only to appropriate users.
Related CVEs
- CVE-2001-1555: Terminal privileges are not reset when a user logs out
- CVE-2001-1514: Incorrect propagation of a security context to child processes can allow privilege escalation
- CVE-2001-0128: Roles are computed incorrectly