CWE-548

Exposure of Information Through Directory Listing

Medium

Description

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Potential Impact

How to Fix

Architecture and Design

Recommendations include restricting access to important directories or files by adopting a need to know requirement for both the document and server root, and turning off features such as Automatic Directory Listings that could expose private files and provide information that could be utilized by an attacker when formulating or conducting an attack.

Detection Methods

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-548 vulnerabilities in your codebase.

Get Security Assessment