9. of Information Disclosure I
An attacker can read sensitive information in a file with bad ACLs.
Or the alternative text:
An attacker can read sensitive information in a file with permissive permissions.
Threat |
|
You created a file with read or write permissions for a group or everyone, but you should be the only person able to access that file and it’s a shared computer/multi-user system. |
|
CAPEC |
CAPEC-127 - Directory Indexing CAPEC-497 - File Discovery |
ASVS |
4.1.3 - Ensure users or services only have the necessary privileges to perform the actions they need to do. 4.3.2 - Ensure directory listing/indexing is disabled. |
CWE |
CWE-921 - Storage of Sensitive Data in a Mechanism without Access... |