Incorrect authorization

Incorrect Authorization

Description

Authorization is incorrect when a system checks permission to access a resource or perform an action, but the check does not enforce the intended policy.

Potential impact

The impact depends on the resource or function that is inadequately protected.

  • Application data access: An attacker may read data from an insufficiently restricted store.
  • Filesystem access: Files or directories may be read or modified without authorization.
  • Privilege escalation: An incorrect permission check may grant elevated privileges.
  • Unauthorized execution: An attacker may abuse permissions to run unauthorized commands or code.
  • Denial of service: Misuse of system resources may disrupt the service.

Remediation

  • Enforce correct authorization checks on every resource and function that needs access control.
  • Use an authentication and authorization framework, such as Spring Security, to simplify protection of sensitive resources.
  • Find and fix missing permission checks through code review and tests.

These examples assume method security is enabled, for example with @EnableMethodSecurity, and calls pass through the security proxy of a Spring-managed bean.

Examples

Before

java
@RestController
public class AdminController {
    @GetMapping("/admin/data")
    public String getAdminData() {
        // No appropriate authorization check for the data
        return "Sensitive admin data";
    }
}

After

java
@RestController
public class AdminController {

    @GetMapping("/admin/data")
    @PreAuthorize("hasRole('ADMIN')")
    public String getAdminData() {
        // Access is limited to users with the ADMIN role
        return "Sensitive admin data";
    }
}

Explanation:

  • Before: This method has no authorization check. Without other access controls, administrative data may be exposed.
  • After: @PreAuthorize restricts method access for /admin/data to the ADMIN role.

Related CVEs

References