Missing authorization

Missing authorization

Description

Missing authorization occurs when an application does not check whether a user is permitted to access a resource or perform an operation.

Potential impact

  • Data access: An attacker may read or modify data through an insufficiently protected store or function.
  • Privilege escalation or bypass: Access to privileged functions or important data may defeat intended access controls.
  • Denial of service: Unauthorized use of resources may consume capacity and disrupt service.

Remediation

  1. Check the required permissions for every user request.
  2. Verify the requester’s role, ownership and other required conditions for each protected endpoint and resource.
  3. Use an authentication and authorization framework such as Spring Security.

Examples

Before

These controller excerpts assume the before example has no separate URL- or service-layer authorization. @PreAuthorize applies only when method security is enabled for the Spring-managed bean. Current configurations use @EnableMethodSecurity; configure authentication and role mapping separately.

java
@GetMapping("/admin")
public String getAdminPage() {
    // Sensitive data or an administrator-only function
    return "admin-page";
}

After

java
@GetMapping("/admin")
@PreAuthorize("hasRole('ROLE_ADMIN')")
public String getAdminPage() {
    // Sensitive data or an administrator-only function
    return "admin-page";
}

Explanation:

  • Before: Shows no access check for /admin. If no other layer restricts access, an unauthorized user may reach the endpoint.
  • After: Uses @PreAuthorize("hasRole('ROLE_ADMIN')") to require the administrator role before invoking /admin, subject to the method-security configuration above.

Related CVEs

References