CSV Request Authorization Should Be Enabled

< 1 min read

Impact Area

Security

Severity

High

Affected Element

System property

Rule ID #

SN-0192

Impact #

Without appropriate authorization configured on the incoming CSV requests, an unauthorized user can get access to sensitive content/data on the target instance.

Remediation #

It is recommended to set this property “glide.basicauth.required.csv” to true, as without appropriate authorization configured on the incoming CSV requests, an unauthorized user can get access to sensitive content/data on the target instance.

Time to fix #

15 min

References #

This rule is linked to Common Weakness Enumeration CWE-862 Missing Authorization.

Updated on March 21, 2025
Was it helpful ?