Description
Missing authorization occurs when an application does not check whether a user is permitted to access a resource or perform an operation.
Potential impact
- Data access: An attacker may read or modify data through an insufficiently protected store or function.
- Privilege escalation or bypass: Access to privileged functions or important data may defeat intended access controls.
- Denial of service: Unauthorized use of resources may consume capacity and disrupt service.
Remediation
- Check the required permissions for every user request.
- Verify the requester’s role, ownership and other required conditions for each protected endpoint and resource.
- Use an authentication and authorization framework such as Spring Security.
Examples
Before
These controller excerpts assume the before example has no separate URL- or service-layer authorization. @PreAuthorize applies only when method security is enabled for the Spring-managed bean. Current configurations use @EnableMethodSecurity; configure authentication and role mapping separately.
java
@GetMapping("/admin")
public String getAdminPage() {
// Sensitive data or an administrator-only function
return "admin-page";
}
After
java
@GetMapping("/admin")
@PreAuthorize("hasRole('ROLE_ADMIN')")
public String getAdminPage() {
// Sensitive data or an administrator-only function
return "admin-page";
}
Explanation:
- Before: Shows no access check for
/admin. If no other layer restricts access, an unauthorized user may reach the endpoint. - After: Uses
@PreAuthorize("hasRole('ROLE_ADMIN')")to require the administrator role before invoking/admin, subject to the method-security configuration above.
Related CVEs
- CVE-2022-24730: Go-based continuous deployment product does not check that a user has certain privileges to update or create an app, allowing adversaries to read sensitive repository information
- CVE-2009-3168: Web application does not restrict access to admin scripts, allowing authenticated users to reset administrative passwords.
- CVE-2009-3597: Web application stores database file under the web root with insufficient access control (CWE-219), allowing direct request.