Umbra Wiki weakness weakness/CWE-566
Back to wiki

CWE-566 — Authorization Bypass Through User-Controlled SQL Primary Key

provenance: imported · CWE: CWE-566

CWE-566: Authorization Bypass Through User-Controlled SQL Primary Key

MITRE CWE weakness

Kind Weakness
Abstraction Variant
Status Incomplete
Likelihood of exploit

Description

The product uses a database table that includes records that should not be accessible to an actor, but it executes a SQL statement with a primary key that can be controlled by that actor.

When a user can set a primary key to any value, then the user can modify the key to point to unauthorized records. Database access control errors occur when: Data enters a program from an untrusted source. The data is used to specify the value of a primary key in a SQL query. The untrusted source does not have the permissions to be able to access all rows in the associated table.

Common consequences

  • Confidentiality, Integrity, Access Control: Read Application Data, Modify Application Data, Bypass Protection Mechanism

Mitigations

Implementation — Assume all input is malicious. Use a standard input validation mechanism to validate all input for length, type, syntax, and business rules before accepting the data. Use an "accept known good" validation strategy.

Implementation — Use a parameterized query AND make sure that the accepted values conform to the business rules. Construct your SQL statement accordingly.

References

  • CWE page: https://cwe.mitre.org/data/definitions/566.html
  • CWE list: https://cwe.mitre.org/data/index.html