CWE一覧に戻る
CWE-293

認証にRefererフィールドを使用する

Using Referer Field for Authentication
脆弱性 レビュー中
JA

HTTPリクエストのrefererフィールドは簡単に変更できるので、メッセージの完全性をチェックする有効な手段ではない。

EN

The referer field in HTTP requests can be easily modified and, as such, is not a valid means of message integrity checking.

Scope: Access Control / Impact: Gain Privileges or Assume Identity
In order to usefully check if a given action is authorized, some means of strong authentication and method protection must be used. Use other means of authorization that cannot be simply spoofed. Possibilities include a username/password or certificate.
MITRE公式ページ — CWE-293