Authenticated route write using predictable IDs

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。

Description

The application may allow users to modify resources they shouldn’t have access to by guessing predictable IDs.

Rationale

Route might be vulnerable to data tampering.

Remediation

  • Validate that users only have access to their own data (AuthZ).