CWE-732
Overview
- CWE ID
- 732
- CWE Name
- Incorrect Permission Assignment for Critical Resource
- CWE Abstraction
- Class
- CWE structure
- Simple
- CWE Status
- Draft
Description
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Extended Description
When a resource is given a permissions setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous