KB / Глосарій / Небезпечне пряме посилання на об'єкт

Небезпечне пряме посилання на об'єкт

Insecure Direct Object Reference
Також: IDOR
web UA EN

IDOR is an access-control vulnerability where the application uses user-supplied object identifiers without authorisation checks.

Example: GET /api/invoice/1337 — changing the ID exposes another user's record.

Mitigation

Per-object authorisation checks, use GUIDs instead of sequential IDs.

Вперше тут?
Новачок на Bastion?
Почни з гайду користувача.
Відкрити гайд →
?