This page is experimental and may change significantly in future releases.
Authorization Bypass Through User-Controlled Key
Properties
id: d3f:CWE-639
- name
- Authorization Bypass Through User-Controlled Key
- definition
- The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
- synonyms
- Broken Object Level Authorization / BOLA
- synonyms
- Horizontal Authorization
- synonyms
- Insecure Direct Object Reference / IDOR
Neighbors
CWE-639 has no direct neighbors in this release.