CWE-612

Improper Authorization of Index Containing Sensitive Information

Medium

Description

The product creates a search index of private or sensitive documents, but it does not properly limit index access to actors who are authorized to see the original information.

Potential Impact

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-612 vulnerabilities in your codebase.

Get Security Assessment