Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-284 (访问控制不恰当) — Vulnerability Class 2613

2613 vulnerabilities classified as CWE-284 (访问控制不恰当). AI Chinese analysis included.

CWE-284 represents a critical security weakness where software fails to properly restrict access to sensitive resources, allowing unauthorized actors to interact with data or functions they should not reach. This flaw typically arises when developers neglect to implement robust authentication or authorization checks, enabling attackers to bypass security controls through direct URL manipulation, token forgery, or privilege escalation techniques. Exploitation often leads to severe consequences, including data breaches, unauthorized system modifications, or complete service disruption. To mitigate this risk, developers must enforce strict access control policies at every layer of the application architecture. This involves implementing comprehensive identity verification, applying the principle of least privilege, and rigorously validating user permissions before granting access to any protected resource, ensuring that only authenticated and authorized users can perform specific actions.

MITRE CWE Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. Access control involves the use of several protection mechanisms such as: Authentication (proving the identity of an actor) Authorization (ensuring that a given actor can access a resource), and Accountability (tracking of activities that were performed) When any mechanism is not applied or otherwise fails, attackers can compromise the security of the product by gaining privileges, reading sensitive information, executing commands, evading detection, etc. There are two distinct behaviors that can introduce access control weaknesses: Specification: incorrect privileges, permissions, ownership, etc. are explicitly specified for either the user or the resource (for example, setting a password file to be world-writable, or giving administrator capabilities to a guest user). This action could be performed by the program or the administrator. Enforcement: the mechanism contains errors that prevent it from properly enforcing the specified access control requirements (e.g., allowing the user to specify their own privileges, or allowing a syntactically-incorrect ACL to produce insecure settings). This problem occurs within the program itself, in that it does not actually enforce the intended security policy that the administrator specifies.
Common Consequences (1)
Other Varies by Context
Mitigations (2)
Architecture and Design, Operation Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
Architecture and Design Compartmentalize the system to have "safe" areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area. Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separatio…
Examples (2)
This code temporarily raises the program's privileges to allow creation of a new user folder.
def makeNewUserDir(username): if invalidUsername(username): #avoid CWE-22 and CWE-78 print('Usernames cannot contain invalid characters') return False try: raisePrivileges() os.mkdir('/home/' + username) lowerPrivileges() except OSError: print('Unable to create new user directory for user:' + username) return False return True
Bad · Python
This function runs an arbitrary SQL query on a given database, returning the result of the query.
function runEmployeeQuery($dbName, $name){ mysql_select_db($dbName,$globalDbHandle) or die("Could not open Database".$dbName); //Use a prepared statement to avoid CWE-89 $preparedStatement = $globalDbHandle->prepare('SELECT * FROM employees WHERE name = :name'); $preparedStatement->execute(array(':name' => $name)); return $preparedStatement->fetchAll(); } /.../ $employeeRecord = runEmployeeQuery('EmployeeDB',$_GET['EmployeeName']);
Bad · PHP
CVE ID Title CVSS Severity Published
CVE-2024-23446 Kibana Broken Access Control issue — Kibana 6.5 Medium 2024-02-07
CVE-2023-32479 Dell 多款产品安全漏洞 — Dell Encryption 6.7 Medium 2024-02-06
CVE-2023-43517 Improper Access Control in Automotive Multimedia — Snapdragon 8.4 High 2024-02-06
CVE-2024-0969 ARMember <= 4.0.24 - Improper Access Control to Sensitive Information Exposure via REST API — ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup 5.3 Medium 2024-02-05
CVE-2024-0373 Views for WPForms <= 3.2.2 - Cross-Site Request Forgery via save_view — Views for WPForms – Display & Edit WPForms Entries on your site frontend 4.3 Medium 2024-02-05
CVE-2024-0366 Starbox – the Author Box for Humans <= 3.4.7 - Insecure Direct Object Reference — Starbox – the Author Box for Humans 4.3 Medium 2024-02-05
CVE-2024-0371 Views for WPForms <= 3.2.2 - Missing Authorization via create_view — Views for WPForms – Display & Edit WPForms Entries on your site frontend 4.3 Medium 2024-02-05
CVE-2024-1092 RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.1 - Missing Authorization — RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator 4.3 Medium 2024-02-05
CVE-2024-0370 Views for WPForms <= 3.2.2 - Missing Authorization via save_view — Views for WPForms – Display & Edit WPForms Entries on your site frontend 4.3 Medium 2024-02-05
CVE-2024-0374 Views for WPForms <= 3.2.2 - Cross-Site Request Forgery via create_view — Views for WPForms – Display & Edit WPForms Entries on your site frontend 4.3 Medium 2024-02-05
CVE-2024-0324 User Profile Builder <= 3.10.8 - Missing Authorization to Plugin Settings Change via wppb_two_factor_authentication_settings_update — User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor 8.2 High 2024-02-05
CVE-2024-22202 User Removal Page Allows Spoofing Of User Details — phpMyFAQ 5.7 Medium 2024-02-05
CVE-2023-38263 IBM SOAR QRadar Plugin App improper access controls — SOAR QRadar Plugin App 6.5 Medium 2024-02-02
CVE-2023-32333 IBM Maximo Asset Management improper access control — Maximo Asset Management 6.5 Medium 2024-02-02
CVE-2023-47867 MachineSense FeverWarn Improper Access Control — FeverWarn 8.8 High 2024-02-01
CVE-2024-1114 openBI Screen.php dlfile access control — openBI 6.5 Medium 2024-01-31
CVE-2024-24566 Lobe Chat unauthorized access to plugins — lobe-chat 5.3 Medium 2024-01-31
CVE-2024-21653 vantage6 insecure SSH configuration for node and server containers — vantage6 6.5 Medium 2024-01-30
CVE-2024-1011 SourceCodester Employee Management System Leave delete-leave.php access control — Employee Management System 4.3 Medium 2024-01-29
CVE-2024-0212 Cloudflare WordPress plugin enables information disclosure of Cloudflare API (for low privileged users) — Cloudflare-WordPress 8.1 High 2024-01-29
CVE-2024-20263 Cisco Small Business 安全漏洞 — Cisco Small Business Smart and Managed Switches 5.8 Medium 2024-01-26
CVE-2024-23675 Splunk App Key Value Store (KV Store) Improper Handling of Permissions Leads to KV Store Collection Deletion — Splunk Enterprise 6.5 Medium 2024-01-22
CVE-2024-23681 Artemis Java Test Sandbox Libary Load Escape 8.6 - 2024-01-19
CVE-2024-0712 Byzoro Smart S150 Management Platform userattea.php access control — Smart S150 Management Platform 7.3 High 2024-01-19
CVE-2023-20260 Cisco Evolved Programmable Network Manager和Cisco Prime Infrastructure安全漏洞 — Cisco Prime Infrastructure 6.0 Medium 2024-01-17
CVE-2024-0642 Inadequate access control in C21 Live Encoder and Live Mosaic — C21 Live Encoder and Live Mosaic 9.8 Critical 2024-01-17
CVE-2024-22407 Broken Access Control order API in Shopware — shopware 4.9 Medium 2024-01-16
CVE-2024-0570 Totolink N350RT Setting cstecgi.cgi access control — N350RT 7.3 High 2024-01-16
CVE-2024-22209 XBlock custom auth does not respect JWT Scopes — edx-platform 6.4 Medium 2024-01-13
CVE-2023-49099 Discourse secure uploads accessible to guests even when login is required — discourse 3.1 Low 2024-01-12

Vulnerabilities classified as CWE-284 (访问控制不恰当) represent 2613 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.