Description
Authorization is incorrect when a system checks permission to access a resource or perform an action, but the check does not enforce the intended policy.
Potential impact
The impact depends on the resource or function that is inadequately protected.
- Application data access: An attacker may read data from an insufficiently restricted store.
- Filesystem access: Files or directories may be read or modified without authorization.
- Privilege escalation: An incorrect permission check may grant elevated privileges.
- Unauthorized execution: An attacker may abuse permissions to run unauthorized commands or code.
- Denial of service: Misuse of system resources may disrupt the service.
Remediation
- Enforce correct authorization checks on every resource and function that needs access control.
- Use an authentication and authorization framework, such as Spring Security, to simplify protection of sensitive resources.
- Find and fix missing permission checks through code review and tests.
These examples assume method security is enabled, for example with @EnableMethodSecurity, and calls pass through the security proxy of a Spring-managed bean.
Examples
Before
java
@RestController
public class AdminController {
@GetMapping("/admin/data")
public String getAdminData() {
// No appropriate authorization check for the data
return "Sensitive admin data";
}
}
After
java
@RestController
public class AdminController {
@GetMapping("/admin/data")
@PreAuthorize("hasRole('ADMIN')")
public String getAdminData() {
// Access is limited to users with the ADMIN role
return "Sensitive admin data";
}
}
Explanation:
- Before: This method has no authorization check. Without other access controls, administrative data may be exposed.
- After:
@PreAuthorizerestricts method access for/admin/datato theADMINrole.
Related CVEs
- CVE-2021-39155: Case-sensitive HTTP Host comparison (CWE-178, CWE-1289) allows mixed-case or variant hostnames to bypass an authorization policy (CWE-863)
- CVE-2019-15900: An unchecked sscanf() return value (CWE-252) leaves an uninitialized value (CWE-457) that allows authorization bypass for a privileged operation (CWE-863)
- CVE-2009-2213: A gateway uses a default Allow authorization configuration