Cross-tenant access to invoice PDFs via predictable object identifiers
- Affected asset
- api.example-app.test/v1/invoices/{id}/pdf
- Technical impact
- Authenticated user of tenant A can retrieve invoices belonging to tenant B.
- Business impact
- Exposure of customer billing data across tenants; contractual and regulatory exposure.
- Remediation
- Enforce tenant ownership check server-side on object lookup; use non-sequential identifiers as defense in depth.
GET /v1/invoices/10482/pdf HTTP/2Authorization: Bearer <tenant-A user token>HTTP/2 200 OKContent-Type: application/pdf · owner: tenant-B