3. of Information Disclosure II
An attacker can see error messages with security-sensitive content.
Threat |
|
An attacker tries to retrieve a report before verifying that the user has sufficient access rights. It fails and the reason you give isn’t related to their permissions but perhaps tells them information relating to the report, such as its security classification. You are, therefore, confirming its existence to the attacker. |
|
CAPEC |
CAPEC-497 - File Discovery CAPEC-694 - System Location Discovery CAPEC-577 - Owner Footprinting CAPEC-576 - Group Permission Footprinting |
ASVS |
7.4.1 - Ensure error messages don’t leak security-sensitive information to the user. |
CWE |
CWE-209 - Generation of... |