CAPEC™ 633: Token Impersonation
Description
An adversary exploits a weakness in authentication to create an access token (or equivalent) that impersonates a different entity, and then associates a process/thread to that that impersonated token. This action causes a downstream user to make a decision or take action that is based on the assumed identity, and not the response that blocks the adversary.
Source: CAPEC™ 633
Related ASVS Requirements
ASVS (5.0): 10.1.1, 10.1.2, 10.2.1, 10.2.2, 10.2.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.4.1, 10.4.10, 10.4.11, 10.4.12, 10.4.13, 10.4.14, 10.4.15, 10.4.16, 10.4.2, 10.4.3, 10.4.4, 10.4.5, 10.4.6, 10.4.7, 10.4.8, 10.4.9, 10.5.1, 10.5.2, 10.5.3, 10.5.4, 10.5.5, 10.6.1, 10.6.2, 10.7.1, 10.7.2, 10.7.3, 12.1.3, 13.2.1, 13.3.4, 14.2.1, 16.3.3, 16.3.4, 4.1.5, 4.4.3, 6.3.6, 6.4.1, 6.5.1, 6.5.5, 6.5.6, 6.5.8, 6.6.1, 6.6.2, 6.8.3, 8.1.3, 8.1.4, 8.2.4, 9.2.1