CWE-638: Not Using Complete Mediation
The product does not perform access checks on a resource every time the resource is accessed by an entity, which can create resultant weaknesses if that entity's rights or privileges change over time.
1 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-56512 — Apache NiFi: Missing Complete Authorization for Parameter and Service References
Recently published
- CVE-2024-56512 — Apache NiFi: Missing Complete Authorization for Parameter and Service References
More specific weaknesses
- CWE-424 — Improper Protection of Alternate Path