CWE-552
Overview
- CWE ID
- 552
- CWE Name
- Files or Directories Accessible to External Parties
- CWE Abstraction
- Base
- CWE structure
- Simple
- CWE Status
- Draft
Description
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Extended Description
Web servers, FTP servers, and similar servers may store a set of files underneath a "root" directory that is accessible to the server's users. Applications may store sensitive files underneath this root without also using access control to limit which us