{"1004": {"name": "Sensitive Cookie Without 'HttpOnly' Flag", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.", "extended_description": "The HttpOnly flag directs compatible browsers to prevent client-side script from accessing cookies. Including the HttpOnly flag in the Set-Cookie HTTP response header helps mitigate the risk associated with Cross-Site Scripting (XSS) where an attacker's script code might attempt to read the contents of a cookie and exfiltrate information obtained. When set, browsers that support the flag will not reveal the contents of the cookie to a third party via client-side script executed via XSS.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Integrity"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Leverage the HttpOnly flag when setting a sensitive cookie in a response.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2024-47833", "description": "python library for ML and data science does not use the HTTPOnly security attribute for session cookies"}, {"cve": "CVE-2022-24045", "description": "Web application for a room automation system has client-side Javascript that sets a sensitive cookie without the HTTPOnly security attribute, allowing..."}, {"cve": "CVE-2014-3852", "description": "CMS written in Python does not include the HTTPOnly flag in a Set-Cookie header, allowing remote attackers to obtain potentially sensitive information..."}, {"cve": "CVE-2015-4138", "description": "Appliance for managing encrypted communications does not use HttpOnly flag."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "1007": {"name": "Insufficient Visual Distinction of Homoglyphs Presented to User", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product displays information or identifiers to a user, but the display mechanism does not make it easy for the user to distinguish between visually similar or identical glyphs (homoglyphs), which may cause the user to misinterpret a glyph and perform an unintended, insecure action.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Integrity", "Confidentiality"], "impact": ["Other"]}], "detection_methods": [{"method": "Manual Dynamic Analysis", "description": "If utilizing user accounts, attempt to submit a username that contains homoglyphs. Similarly, check to see if links containing homoglyphs can be sent via email, web browsers, or other mechanisms."}], "observed_examples": [{"cve": "CVE-2013-7236", "description": "web forum allows impersonation of users with homoglyphs in account names"}, {"cve": "CVE-2012-0584", "description": "Improper character restriction in URLs in web browser"}, {"cve": "CVE-2009-0652", "description": "Incomplete denylist does not include homoglyphs of \"/\" and \"?\" characters in URLs"}, {"cve": "CVE-2017-5015", "description": "web browser does not convert hyphens to punycode, allowing IDN spoofing in URLs"}, {"cve": "CVE-2005-0233", "description": "homoglyph spoofing using punycode in URLs and certificates"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "102": {"name": "Struts: Duplicate Validation Forms", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses multiple validation forms with the same name, which might cause the Struts Validator to validate a form that the programmer does not expect.", "extended_description": "If two validation forms have the same name, the Struts Validator arbitrarily chooses one of the forms to use for input validation and discards the other. This decision might not correspond to the programmer's expectations, possibly leading to resultant weaknesses. Moreover, it indicates that the validation logic is not up-to-date, and can indicate that other, more subtle validation errors are present.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "The DTD or schema validation will not catch the duplicate occurrence of the same form name. To find the issue in the implementation, manual checks or automated static analysis could be applied to the xml configuration files.", "phase": ["Implementation"]}], "platforms": {"languages": ["Java"]}}, "1021": {"name": "Improper Restriction of Rendered UI Layers or Frames", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.", "extended_description": "A web application is expected to place restrictions on whether it is allowed to be rendered within frames, iframes, objects, embed or applet elements. Without the restrictions, users can be tricked into interacting with the application when they were not intending to.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Read Application Data", "Modify Application Data"]}], "mitigations": [{"description": "This defense-in-depth technique can be used to prevent the improper usage of frames in web applications. It prioritizes the valid sources of data to be loaded into the application through the usage of declarative policies. Based on which implementation of Content Security Policy is in use, the devel...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2017-7440", "description": "E-mail preview feature in a desktop application allows clickjacking attacks via a crafted e-mail message"}, {"cve": "CVE-2017-5697", "description": "Hardware/firmware product has insufficient clickjacking protection in its web user interface"}, {"cve": "CVE-2017-4015", "description": "Clickjacking in data-loss prevention product via HTTP response header."}, {"cve": "CVE-2016-2496", "description": "Tapjacking in permission dialog for mobile OS allows access of private storage using a partially-overlapping window."}, {"cve": "CVE-2015-1241", "description": "Tapjacking in web browser related to page navigation and touch/gesture events."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "1022": {"name": "Use of Web Link to Untrusted Target with window.opener Access", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The web application produces links to untrusted external sites outside of its sphere of control, but it does not properly prevent the external site from modifying security-critical properties of the window.opener object, such as the location property.", "extended_description": "When a user clicks a link to an external site (\"target\"), the target=\"_blank\" attribute causes the target site's contents to be opened in a new window or tab, which runs in the same process as the original page. The window.opener object records information about the original page that offered the link.  If an attacker can run script on the target page, then they could read or modify certain properties of the window.opener object, including the location property - even if the original and target ...", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality"], "impact": ["Alter Execution Logic"]}], "mitigations": [{"description": "Specify in the design that any linked external document must not be granted access to the location object of the calling page.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-4927", "description": "Library software does not use rel: \"noopener noreferrer\" setting, allowing tabnabbing attacks to redirect to a malicious page"}], "platforms": {"languages": ["Not Language-Specific", "JavaScript"], "technologies": ["Web Based", "Web Server"]}}, "1023": {"name": "Incomplete Comparison with Missing Factors", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product performs a comparison between entities that must consider multiple factors or characteristics of each entity, but the comparison does not include one or more of these factors.", "consequences": [{"scope": ["Integrity", "Access Control"], "impact": ["Alter Execution Logic", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Thoroughly test the comparison scheme before deploying code into production. Perform positive testing as well as negative testing.", "phase": ["Testing"]}], "observed_examples": [{"cve": "CVE-2005-2782", "description": "PHP remote file inclusion in web application that filters \"http\" and \"https\" URLs, but not \"ftp\"."}, {"cve": "CVE-2014-6394", "description": "Product does not prevent access to restricted directories due to partial string comparison with a public directory"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1024": {"name": "Comparison of Incompatible Types", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product performs a comparison between two entities, but the entities are of different, incompatible types that cannot be guaranteed to provide correct results when they are directly compared.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Thoroughly test the comparison scheme before deploying code into production. Perform positive testing as well as negative testing.", "phase": ["Testing"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["JavaScript", "PHP", "Not Language-Specific"]}}, "1025": {"name": "Comparison Using Wrong Factors", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The code performs a comparison between two entities, but the comparison examines the wrong factors or characteristics of the entities, which can lead to incorrect results and resultant weaknesses.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Thoroughly test the comparison scheme before deploying code into production. Perform positive testing as well as negative testing.", "phase": ["Testing"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "103": {"name": "Struts: Incomplete validate() Method Definition", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product has a validator form that either does not define a validate() method, or defines a validate() method but does not call super.validate().", "consequences": [{"scope": ["Other"], "impact": ["Unexpected State", "Varies by Context"]}, {"scope": ["Confidentiality", "Integrity", "Availability", "Other"], "impact": ["Other"]}], "mitigations": [{"description": "Implement the validate() method and call super.validate() within that method.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "1037": {"name": "Processor Optimization Removal or Modification of Security-critical Code", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The developer builds a security-critical protection mechanism into the software, but the processor optimizes the execution of the program such that the mechanism is removed or modified.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Integrity"], "impact": ["Bypass Protection Mechanism"]}], "detection_methods": [{"method": "White Box", "description": "In theory this weakness can be detected through the use of white box testing techniques where specifically crafted test cases are used in conjunction with debuggers to verify the order of statements b..."}], "observed_examples": [{"cve": "CVE-2017-5715", "description": "Intel, ARM, and AMD processor optimizations related to speculative execution and branch prediction cause access control checks to be bypassed when pla..."}, {"cve": "CVE-2017-5753", "description": "Intel, ARM, and AMD processor optimizations related to speculative execution and branch prediction cause access control checks to be bypassed when pla..."}, {"cve": "CVE-2017-5754", "description": "Intel processor optimizations related to speculative execution cause access control checks to be bypassed when placing data into the cache. Often know..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Processor Hardware"]}}, "1038": {"name": "Insecure Automated Optimizations", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product uses a mechanism that automatically optimizes code, e.g. to improve a characteristic such as performance, but the optimizations can have an unintended side effect that might violate an intended security assumption.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Integrity"], "impact": ["Alter Execution Logic"]}], "observed_examples": [{"cve": "CVE-2017-5715", "description": "Intel, ARM, and AMD processor optimizations related to speculative execution and branch prediction cause access control checks to be bypassed when pla..."}, {"cve": "CVE-2008-1685", "description": "C compiler optimization, as allowed by specifications, removes code that is used to perform checks to detect integer overflows."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1039": {"name": "Inadequate Detection or Handling of Adversarial Input Perturbations in Automated Recognition Mechanism", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product uses an automated mechanism such as machine learning to recognize complex data inputs (e.g. image or audio) as a particular concept or category, but it does not properly detect or handle inputs that have been modified or constructed in a way that causes the mechanism to detect a different, incorrect concept.", "consequences": [{"scope": ["Integrity"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Availability"], "impact": ["DoS: Resource Consumption (Other)", "DoS: Instability"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Algorithmic modifications such as model pruning or compression can help mitigate this weakness. Model pruning ensures that only weights that are most relevant to the task are used in the inference of incoming data and has shown resilience to adversarial perturbed data.", "phase": ["Architecture and Design"]}, {"description": "Consider implementing adversarial training, a method that introduces adversarial examples into the training data to promote robustness of algorithm at inference time.", "phase": ["Architecture and Design"]}, {"description": "Consider implementing model hardening to fortify the internal structure of the algorithm, including techniques such as regularization and optimization to desensitize algorithms to minor input perturbations and/or changes.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Dynamic Analysis with Manual Results Interpretation", "description": "Use indicators from model performance deviations such as sudden drops in accuracy or unexpected outputs to verify the model."}, {"method": "Dynamic Analysis with Manual Results Interpretation", "description": "Use indicators from input data collection mechanisms to verify that inputs are statistically within the distribution of the training and test data."}, {"method": "Architecture or Design Review", "description": "Use multiple models or model ensembling techniques to check for consistency of predictions/inferences."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["AI/ML"]}}, "104": {"name": "Struts: Form Bean Does Not Extend Validation Class", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "If a form bean does not extend an ActionForm subclass of the Validator framework, it can expose the application to other weaknesses related to insufficient input validation.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}, {"scope": ["Confidentiality", "Integrity", "Availability", "Other"], "impact": ["Other"]}], "mitigations": [{"description": "Ensure that all forms extend one of the Validation Classes.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "1041": {"name": "Use of Redundant Code", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product has multiple functions, methods, procedures, macros, etc. that\n\t\t\t\t\tcontain the same code.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "mitigations": [{"description": "Merge common functionality into a single function and then call that function from across the entire code base.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1042": {"name": "Static Member Data Element outside of a Singleton Class Element", "abstraction": "Variant", "mapping": "PROHIBITED", "structure": "Simple", "description": "The code contains a member element that is declared as static (but not final), in which\n\t\t\t\t\tits parent class element \n\t\t\t\t\tis not a singleton class - that is, a class element that can be used only once in\n\t\t\t\t\tthe 'to' association of a Create action.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Performance"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1043": {"name": "Data Element Aggregating an Excessively Large Number of Non-Primitive Elements", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product uses a data element that has an excessively large\n\t\t\t\t\tnumber of sub-elements with non-primitive data types such as structures or aggregated objects.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Performance"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1044": {"name": "Architecture with Number of Horizontal Layers Outside of Expected Range", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product's architecture contains too many - or too few -\n\t\t\t\t\thorizontal layers.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1045": {"name": "Parent Class with a Virtual Destructor and a Child Class without a Virtual Destructor", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A parent class has a virtual destructor method, but the parent has a child class that does not have a virtual destructor.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1046": {"name": "Creation of Immutable Text Using String Concatenation", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product creates an immutable text string using string concatenation operations.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Performance"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1047": {"name": "Modules with Circular Dependencies", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product contains modules in which one module has references that cycle back to itself, i.e., there are circular dependencies.", "extended_description": "As an example, with Java, this weakness might indicate cycles between packages.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1048": {"name": "Invokable Control Element with Large Number of Outward Calls", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The code contains callable control elements that\n         contain an excessively large number of references to other\n         application objects external to the context of the callable,\n         i.e. a Fan-Out value that is excessively large.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1049": {"name": "Excessive Data Query Operations in a Large Data Table", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product performs a data query with a large number of joins\n\t\t\t\t\tand sub-queries on a large data table.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Performance"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "105": {"name": "Struts: Form Field Without Validator", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product has a form field that is not validated by a corresponding validation form, which can introduce other weaknesses related to insufficient input validation.", "extended_description": "Omitting validation for even a single input field may give attackers the leeway they need to compromise the product. Although J2EE applications are not generally susceptible to memory corruption attacks, if a J2EE application interfaces with native code that does not perform array bounds checking, an attacker may be able to use an input validation mistake in the J2EE application to launch a buffer overflow attack.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}, {"scope": ["Integrity"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Validate all form fields. If a field is unused, it is still important to constrain it so that it is empty or undefined.", "phase": ["Implementation"]}], "platforms": {"languages": ["Java"]}}, "1050": {"name": "Excessive Platform Resource Consumption within a Loop", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product has a loop body or loop condition that contains a control element that directly or\n\t\t\t\t\tindirectly consumes platform resources, e.g. messaging, sessions, locks, or file\n\t\t\t\t\tdescriptors.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Resource Consumption (Other)", "Reduce Performance"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1051": {"name": "Initialization with Hard-Coded Network Resource Configuration Data", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product initializes data using hard-coded values that act as network resource identifiers.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1052": {"name": "Excessive Use of Hard-Coded Literals in Initialization", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product initializes a data element using a hard-coded\n\t\t\t\t\tliteral that is not a simple integer or static constant element.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1053": {"name": "Missing Documentation for Design", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product does not have documentation that represents how it is designed.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1054": {"name": "Invocation of a Control Element at an Unnecessarily Deep Horizontal Layer", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The code at one architectural layer invokes code that resides\n\t\t\t\t\tat a deeper layer than the adjacent layer, i.e., the invocation skips at least one\n\t\t\t\t\tlayer, and the invoked code is not part of a vertical utility layer that can be referenced from any horizontal layer.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1055": {"name": "Multiple Inheritance from Concrete Classes", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product contains a class with inheritance from more than\n\t\t\t\t\tone concrete class.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1056": {"name": "Invokable Control Element with Variadic Parameters", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "A named-callable or method control element has a signature that\n\t\t\t\t\tsupports a variable (variadic) number of parameters or arguments.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1057": {"name": "Data Access Operations Outside of Expected Data Manager Component", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product uses a dedicated, central data manager component as required by design, but it contains code that performs data-access operations that do not use this data manager.", "consequences": [{"scope": ["Availability"], "impact": ["Reduce Performance"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1058": {"name": "Invokable Control Element in Multi-Thread Context with non-Final Static Storable or Member Element", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The code contains a function or method that\n\t\t operates in a multi-threaded environment but owns an unsafe non-final\n\t\t                     static storable or member data element.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1059": {"name": "Insufficient Technical Documentation", "abstraction": "Class", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product does not contain sufficient\n         technical or engineering documentation (whether on paper or\n         in electronic form) that contains descriptions of all the\n         relevant software/hardware elements of the product, such as\n         its usage, structure, architectural components, interfaces, design, implementation,\n         configuration, operation, etc.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context", "Hide Activities", "Reduce Reliability", "Quality Degradation", "Reduce Maintainability"]}], "mitigations": [{"description": "Ensure that design documentation is detailed enough to allow for post-manufacturing verification.", "phase": ["Documentation", "Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2022-3203", "description": "A wireless access point manual specifies that the only method of configuration is via web interface (CWE-1059), but there is an undisclosed telnet ser..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "ICS/OT"]}}, "106": {"name": "Struts: Plug-in Framework not in Use", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "When an application does not use an input validation framework such as the Struts Validator, there is a greater risk of introducing weaknesses related to insufficient input validation.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Use an input validation framework such as Struts.", "phase": ["Architecture and Design"]}, {"description": "Use an input validation framework such as Struts.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Java"]}}, "1060": {"name": "Excessive Number of Inefficient Server-Side Data Accesses", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product performs too many data queries without using efficient data processing functionality such as stored procedures.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Performance"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1061": {"name": "Insufficient Encapsulation", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not sufficiently hide the internal representation and implementation details of data or methods, which might allow external components or modules to modify data unexpectedly, invoke unexpected functionality, or introduce dependencies that the programmer did not intend.", "consequences": [{"scope": ["Access Control"], "impact": ["Varies by Context", "Bypass Protection Mechanism"]}, {"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2010-3860", "description": "variables declared public allow remote read of system properties such as user name and home directory."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1062": {"name": "Parent Class with References to Child Class", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The code has a parent class that contains references to a child class, its methods, or its members.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1063": {"name": "Creation of Class Instance within a Static Code Block", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "A static code block creates an instance of a class.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Performance"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1064": {"name": "Invokable Control Element with Signature Containing an Excessive Number of Parameters", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product contains a function, subroutine, or method whose signature has an unnecessarily large number of\n\t\t\t\t\tparameters/arguments.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1065": {"name": "Runtime Resource Management Control Element in a Component Built to Run on Application Servers", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product uses deployed components from application servers, but it also uses low-level functions/methods for management of resources, instead of the API provided by the application server.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1066": {"name": "Missing Serialization Control Element", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product contains a serializable data element that does not\n\t\t\t\t\thave an associated serialization method.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1067": {"name": "Excessive Execution of Sequential Searches of Data Resource", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains a data query against an SQL table or view\n\t\t\t\t\tthat is configured in a way that does not utilize an index and may cause\n\t\t\t\t\tsequential searches to be performed.", "consequences": [{"scope": ["Availability"], "impact": ["Reduce Performance"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1068": {"name": "Inconsistency Between Implementation and Documented Design", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The implementation of the product is not consistent with the\n\t\t\t\t\tdesign as described within the relevant documentation.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "platforms": {"technologies": ["Not Technology-Specific", "ICS/OT"]}}, "1069": {"name": "Empty Exception Block", "abstraction": "Variant", "mapping": "PROHIBITED", "structure": "Simple", "description": "An invokable code block contains an exception handling block that does not contain any code, i.e. is empty.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "mitigations": [{"description": "For every exception block add code that handles the specific exception in the way intended by the application.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "107": {"name": "Struts: Unused Validation Form", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "An unused validation form indicates that validation logic is not up-to-date.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "mitigations": [{"description": "Remove the unused Validation Form from the validation.xml file.", "phase": ["Implementation"]}], "platforms": {"languages": ["Java"]}}, "1070": {"name": "Serializable Data Element Containing non-Serializable Item Elements", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product contains a serializable, storable data element such as a field or member,\n\t\t\t\t\tbut the data element contains member elements that are not\n\t\t\t\t\tserializable.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1071": {"name": "Empty Code Block", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The source code contains a block that does not contain any code, i.e., the block is empty.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1072": {"name": "Data Resource Access without Use of Connection Pooling", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product accesses a data resource through a database without using a\n\t\t\t\t\tconnection pooling capability.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Performance"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1073": {"name": "Non-SQL Invokable Control Element with Excessive Number of Data Resource Accesses", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product contains a client with a function or method that contains a large number of data accesses/queries that are sent through a data manager, i.e., does not use efficient database capabilities.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Performance"]}], "platforms": {"languages": ["SQL"], "technologies": ["Database Server"]}}, "1074": {"name": "Class with Excessively Deep Inheritance", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "A class has an inheritance level that is too high, i.e., it\n\t\t\t\t\thas a large number of parent classes.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1075": {"name": "Unconditional Control Flow Transfer outside of Switch Block", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product performs unconditional control transfer (such as a\n\t\t\t\t\t\"goto\") in code outside of a branching structure such as a switch\n\t\t\t\t\tblock.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1076": {"name": "Insufficient Adherence to Expected Conventions", "abstraction": "Class", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product's architecture, source code, design, documentation,\n\t\t\t\t\tor other artifact does not follow required conventions.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1077": {"name": "Floating Point Comparison with Incorrect Operator", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The code performs a comparison such as an\n        equality test between two float (floating point) values, but\n        it uses comparison operators that do not account for the\n        possibility of loss of precision.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1078": {"name": "Inappropriate Source Code Style or Formatting", "abstraction": "Class", "mapping": "PROHIBITED", "structure": "Simple", "description": "The source code does not follow\n\t\t\t\tdesired style or formatting for indentation, white\n\t\t\t\tspace, comments, etc.", "consequences": [{"scope": ["Other"], "impact": ["Increase Analytical Complexity"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1079": {"name": "Parent Class without Virtual Destructor Method", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A parent class contains one or more child classes, but the parent class does not have a virtual destructor method.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "108": {"name": "Struts: Unvalidated Action Form", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Every Action Form must have a corresponding validation form.", "extended_description": "If a Struts Action Form Mapping specifies a form, it must have a validation form defined under the Struts Validator.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}, {"scope": ["Confidentiality", "Integrity", "Availability", "Other"], "impact": ["Other"]}], "platforms": {"languages": ["Java"]}}, "1080": {"name": "Source Code File with Excessive Number of Lines of Code", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "A source code file has too many lines of\n\t\t\t\t\tcode.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1082": {"name": "Class Instance Self Destruction Control Element", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The code contains a class instance that calls the method or function to delete or destroy itself.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1083": {"name": "Data Access from Outside Expected Data Manager Component", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product is intended to manage data access through a particular data manager component such as a relational or non-SQL database, but it contains code that performs data access operations without using that component.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1084": {"name": "Invokable Control Element with Excessive File or Data Access Operations", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "A function or method contains too many\n\t\t\t\t\toperations that utilize a data manager or file resource.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1085": {"name": "Invokable Control Element with Excessive Volume of Commented-out Code", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "A function, method, procedure, etc. contains an excessive amount of code that has been\n\t\t\t\t\tcommented out within its body.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1086": {"name": "Class with Excessive Number of Child Classes", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "A class contains an unnecessarily large number of\n\t\t\t\t\tchildren.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "platforms": {"languages": ["Object-Oriented"]}}, "1087": {"name": "Class with Virtual Method without a Virtual Destructor", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A class contains a virtual method, but the method does not have an associated virtual destructor.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Object-Oriented"]}}, "1088": {"name": "Synchronous Access of Remote Resource without Timeout", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The code has a synchronous call to a remote resource, but there is no timeout for the call, or the timeout is set to infinite.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1089": {"name": "Large Data Table with Excessive Number of Indices", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a large data table that contains an excessively large number of\n\t\t\t\t\tindices.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Performance"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "109": {"name": "Struts: Validator Turned Off", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Automatic filtering via a Struts bean has been turned off, which disables the Struts Validator and custom validation logic. This exposes the application to other weaknesses related to insufficient input validation.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Ensure that an action form mapping enables validation. Set the validate field to true.", "phase": ["Implementation"]}], "platforms": {"languages": ["Java"]}}, "1090": {"name": "Method Containing Access of a Member Element from Another Class", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "A method for a class performs an operation that directly\n\t\t\t\t\taccesses a member element from another class.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "platforms": {"languages": ["Object-Oriented"]}}, "1091": {"name": "Use of Object without Invoking Destructor Method", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains a method that accesses an object but does not later invoke\n\t\t\t\t\tthe element's associated finalize/destructor method.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Performance"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Object-Oriented"]}}, "1092": {"name": "Use of Same Invokable Control Element in Multiple Architectural Layers", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product uses the same control element across multiple\n\t\t\t\t\tarchitectural layers.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1093": {"name": "Excessively Complex Data Representation", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product uses an unnecessarily complex internal representation for its data structures or interrelationships between those structures.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}, {"scope": ["Other"], "impact": ["Reduce Performance"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1094": {"name": "Excessive Index Range Scan for a Data Resource", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product contains an index range scan for a large data table,\n\t\t\t\t\tbut the scan can cover a large number of rows.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Performance"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1095": {"name": "Loop Condition Value Update within the Loop", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product uses a loop with a control flow condition based on\n\t\t\t\t\ta value that is updated within the body of the loop.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1096": {"name": "Singleton Class Instance Creation without Proper Locking or Synchronization", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product implements a Singleton design pattern but does not use appropriate locking or other synchronization mechanism to ensure that the singleton class is only instantiated once.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1097": {"name": "Persistent Storable Data Element without Associated Comparison Control Element", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product uses a storable data element that does not have\n\t\t\t\t\tall of the associated functions or methods that are necessary to support\n\t\t\t\t\tcomparison.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1098": {"name": "Data Element containing Pointer Item without Proper Copy Control Element", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The code contains a data element with a pointer that does not have an associated copy or constructor method.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1099": {"name": "Inconsistent Naming Conventions for Identifiers", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product's code, documentation, or other artifacts do not\n\t\t\t\t\tconsistently use the same naming conventions for variables, callables, groups of\n\t\t\t\t\trelated callables, I/O capabilities, data types, file names, or similar types of\n\t\t\t\t\telements.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "11": {"name": "ASP.NET Misconfiguration: Creating Debug Binary", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Debugging messages help attackers learn about the system and plan a form of attack.", "extended_description": "ASP .NET applications can be configured to produce debug binaries. These binaries give detailed debugging messages and should not be used in production environments. Debug binaries are meant to be used in a development or testing environment and can pose a security risk if they are deployed to production.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Avoid releasing debug binaries into the production environment. Change the debug mode to false when the application is deployed into production.", "phase": ["System Configuration"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["ASP.NET"]}}, "110": {"name": "Struts: Validator Without Form Field", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Validation fields that do not appear in forms they are associated with indicate that the validation logic is out of date.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "To find the issue in the implementation, manual checks or automated static analysis could be applied to the XML configuration files."}, {"method": "Manual Static Analysis", "description": "To find the issue in the implementation, manual checks or automated static analysis could be applied to the XML configuration files."}], "platforms": {"languages": ["Java"]}}, "1100": {"name": "Insufficient Isolation of System-Dependent Functions", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product or code does not isolate system-dependent\n\t\t\t\t\tfunctionality into separate standalone modules.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1101": {"name": "Reliance on Runtime Component in Generated Code", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product uses automatically-generated code that cannot be\n\t\t\t\t\texecuted without a specific runtime support component.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1102": {"name": "Reliance on Machine-Dependent Data Representation", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The code uses a data representation that relies on low-level\n\t\t\t\t\tdata representation or constructs that may vary across different processors,\n\t\t\t\t\tphysical machines, OSes, or other physical components.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1103": {"name": "Use of Platform-Dependent Third Party Components", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product relies on third-party components that do\n\t\t\t\t\tnot provide equivalent functionality across all desirable\n\t\t\t\t\tplatforms.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1104": {"name": "Use of Unmaintained Third Party Components", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product relies on third-party components that are not\n\t\t\t\t\tactively supported or maintained by the original developer or a trusted proxy\n\t\t\t\t\tfor the original developer.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Varies by Context"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "ICS/OT"]}}, "1105": {"name": "Insufficient Encapsulation of Machine-Dependent Functionality", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product or code uses machine-dependent functionality, but\n\t\t\t\t\tit does not sufficiently encapsulate or isolate this functionality from\n\t\t\t\t\tthe rest of the code.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1106": {"name": "Insufficient Use of Symbolic Constants", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The source code uses literal constants that may need to change\n\t\t\t\t\tor evolve over time, instead of using symbolic constants.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1107": {"name": "Insufficient Isolation of Symbolic Constant Definitions", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The source code uses symbolic constants, but it does not\n\t\t\t\t\tsufficiently place the definitions of these constants into a more centralized or\n\t\t\t\t\tisolated location.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1108": {"name": "Excessive Reliance on Global Variables", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The code is structured in a way that relies too much on using\n\t\t\t\t\tor setting global variables throughout various points in the code, instead of\n\t\t\t\t\tpreserving the associated information in a narrower, more local\n\t\t\t\t\tcontext.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1109": {"name": "Use of Same Variable for Multiple Purposes", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The code contains a callable, block, or other code element in\n\t\t\t\t\twhich the same variable is used to control more than one unique task or store\n\t\t\t\t\tmore than one instance of data.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}, {"scope": ["Other"], "impact": ["Increase Analytical Complexity"]}], "observed_examples": [{"cve": "CVE-2023-26463", "description": "Chain: IPSec VPN product uses the same variable for multiple purposes in the same function (CWE-1109), leading to incorrect access control (CWE-284) a..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "111": {"name": "Direct Use of Unsafe JNI", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "When a Java application uses the Java Native Interface (JNI) to call code written in another programming language, it can expose the application to weaknesses in that code, even if those weaknesses cannot occur in Java.", "extended_description": "Many safety features that programmers may take for granted do not apply for native code, so you must carefully review all such code for potential problems. The languages used to implement native code may be more susceptible to buffer overflows and other attacks. Native code is unprotected by the security features enforced by the runtime environment, such as strong typing and array bounds checking.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Implement error handling around the JNI call.", "phase": ["Implementation"]}, {"description": "Do not use JNI calls if you don't trust the native library.", "phase": ["Implementation"]}, {"description": "Be reluctant to use JNI calls. A Java API equivalent may exist.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "1110": {"name": "Incomplete Design Documentation", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product's design documentation does not adequately describe\n\t\t\t\t\tcontrol flow, data flow, system initialization, relationships between tasks,\n\t\t\t\t\tcomponents, rationales, or other important aspects of the\n\t\t\t\t\tdesign.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}, {"scope": ["Other"], "impact": ["Increase Analytical Complexity"]}], "platforms": {"technologies": ["Not Technology-Specific", "ICS/OT"]}}, "1111": {"name": "Incomplete I/O Documentation", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product's documentation does not adequately define inputs,\n\t\t\t\t\toutputs, or system/software interfaces.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}, {"scope": ["Other"], "impact": ["Increase Analytical Complexity"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1112": {"name": "Incomplete Documentation of Program Execution", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The document does not fully define all mechanisms that are used\n\t\t\t\t\tto control or influence how product-specific programs are\n\t\t\t\t\texecuted.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}, {"scope": ["Other"], "impact": ["Increase Analytical Complexity"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1113": {"name": "Inappropriate Comment Style", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The source code uses comment styles or formats that are\n\t\t\t\t\tinconsistent or do not follow expected standards for the\n\t\t\t\t\tproduct.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}, {"scope": ["Other"], "impact": ["Increase Analytical Complexity"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1114": {"name": "Inappropriate Whitespace Style", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The source code contains whitespace that is inconsistent across\n\t\t\t\t\tthe code or does not follow expected standards for the\n\t\t\t\t\tproduct.", "consequences": [{"scope": ["Other"], "impact": ["Increase Analytical Complexity"]}, {"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "observed_examples": [{"cve": "CVE-2014-1266", "description": "Chain: incorrect \"goto\" in Apple SSL product bypasses certificate validation, allowing Adversary-in-the-Middle (AITM) attack (Apple \"goto fail\" bug). ..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1115": {"name": "Source Code Element without Standard Prologue", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The source code contains elements such as source files \n\t\t\t\t\tthat do not consistently provide a prologue or header that has been\n\t\t\t\t\tstandardized for the project.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}, {"scope": ["Other"], "impact": ["Increase Analytical Complexity"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1116": {"name": "Inaccurate Source Code Comments", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The source code contains comments that do not accurately\n\t\t\t\t\tdescribe or explain aspects of the portion of the code with which the comment is\n\t\t\t\t\tassociated.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}, {"scope": ["Other"], "impact": ["Increase Analytical Complexity"]}], "mitigations": [{"description": "Verify that each comment accurately reflects what is intended to happen during execution of the code.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1117": {"name": "Callable with Insufficient Behavioral Summary", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The code contains a function or method whose signature and/or associated\n\t\t\t\t\tinline documentation does not sufficiently describe the callable's inputs, outputs,\n\t\t\t\t\tside effects, assumptions, or return codes.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1118": {"name": "Insufficient Documentation of Error Handling Techniques", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The documentation does not sufficiently describe the techniques\n\t\t\t\t\tthat are used for error handling, exception processing, or similar\n\t\t\t\t\tmechanisms.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1119": {"name": "Excessive Use of Unconditional Branching", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The code uses too many unconditional branches (such as\n\t\t\t\t\t\"goto\").", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "112": {"name": "Missing XML Validation", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts XML from an untrusted source but does not validate the XML against the proper schema.", "extended_description": "Most successful attacks begin with a violation of the programmer's assumptions. By accepting an XML document without validating it against a DTD or XML schema, the programmer leaves a door open for attackers to provide unexpected, unreasonable, or malicious input.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1120": {"name": "Excessive Code Complexity", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The code is too complex, as calculated using a well-defined,\n\t\t\t\t\tquantitative measure.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}, {"scope": ["Other"], "impact": ["Reduce Performance"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1121": {"name": "Excessive McCabe Cyclomatic Complexity", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The code contains McCabe cyclomatic complexity that exceeds a\n\tdesirable maximum.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1122": {"name": "Excessive Halstead Complexity", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The code is structured in a way that a Halstead complexity\n\t\t\t\t\tmeasure exceeds a desirable maximum.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1123": {"name": "Excessive Use of Self-Modifying Code", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses too much self-modifying code.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1124": {"name": "Excessively Deep Nesting", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The code contains a callable or other code grouping in which\n\t\t\t\t\tthe nesting / branching is too deep.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1125": {"name": "Excessive Attack Surface", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "The product has an attack surface whose quantitative\n\t\t\t\t\tmeasurement exceeds a desirable maximum.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1126": {"name": "Declaration of Variable with Unnecessarily Wide Scope", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The source code declares a variable in one scope, but the\n\t\t\t\t\tvariable is only used within a narrower scope.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Increase Analytical Complexity"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1127": {"name": "Compilation with Insufficient Warnings or Errors", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The code is compiled without sufficient warnings enabled, which\n\t\t\t\t\tmay prevent the detection of subtle bugs or quality\n\t\t\t\t\tissues.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "detection_methods": [{"method": "Manual Analysis", "description": "Inspect scripts and tools that invoke the\n\t     compiler. Ensure that the appropriate command line\n\t     switches and/or configuration are specified to report\n\t     warnings and errors."}], "platforms": {"languages": ["Compiled", "Not Language-Specific"]}}, "113": {"name": "Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.", "consequences": [{"scope": ["Integrity", "Access Control"], "impact": ["Modify Application Data", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Construct HTTP headers very carefully, avoiding the use of non-validated input data.", "phase": ["Implementation"]}, {"description": "Use and specify an output encoding that can be handled by the downstream component that is reading the output. Common encodings include ISO-8859-1, UTF-7, and UTF-8. When an encoding is not specified, a downstream component may choose a different encoding, either by assuming a default encoding or au...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2020-15811", "description": "Chain: Proxy uses a substring search instead of parsing the Transfer-Encoding header (CWE-697), allowing request splitting (CWE-113) and cache poisoni..."}, {"cve": "CVE-2021-41084", "description": "Scala-based HTTP interface allows request splitting and response splitting through header names, header values, status reasons, and URIs"}, {"cve": "CVE-2018-12116", "description": "Javascript-based framework allows request splitting through a path option of an HTTP request"}, {"cve": "CVE-2004-2146", "description": "Application accepts CRLF in an object ID, allowing HTTP response splitting."}, {"cve": "CVE-2004-1656", "description": "Shopping cart allows HTTP response splitting to perform HTML injection via CRLF in a parameter for a url"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "114": {"name": "Process Control", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "Executing commands or loading libraries from an untrusted source or in an untrusted environment can cause an application to execute malicious commands (and payloads) on behalf of an attacker.", "extended_description": "Process control vulnerabilities take two forms:", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Libraries that are loaded should be well understood and come from a trusted source. The application can execute code contained in the native libraries, which often contain calls that are susceptible to other security problems, such as buffer overflows or command injection. All native libraries shoul...", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "115": {"name": "Misinterpretation of Input", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product misinterprets an input, whether from an attacker or another product, in a security-relevant fashion.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}], "observed_examples": [{"cve": "CVE-2005-2225", "description": "Product sees dangerous file extension in free text of a group discussion, disconnects all users."}, {"cve": "CVE-2001-0003", "description": "Product does not correctly import and process security settings from another product."}], "platforms": {"languages": ["Not Language-Specific"]}}, "116": {"name": "Improper Encoding or Escaping of Output", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}, {"scope": ["Integrity", "Confidentiality", "Availability", "Access Control"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Confidentiality"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Understand the context in which your data will be used and the encoding that will be expected. This is especially important when transmitting data between different components, or when generating outputs that can contain multiple encodings at the same time, such as web pages or multi-part mail messa...", "phase": ["Architecture and Design", "Implementation"]}, {"description": "In some cases, input validation may be an important strategy when output encoding is not a complete solution. For example, you may be providing the same output that will be processed by multiple consumers that use different encodings or representations. In other cases, you may be required to allow u...", "phase": ["Architecture and Design"]}, {"description": "Use input validation as a defense-in-depth measure to reduce the likelihood of output encoding errors (see CWE-20).", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "This weakness can often be detected using automated static analysis tools. Many modern tools use data flow analysis or constraint-based techniques to minimize the number of false positives."}, {"method": "Automated Dynamic Analysis", "description": "This weakness can be detected using dynamic tools and techniques that interact with the software using large test suites with many diverse inputs, such as fuzz testing (fuzzing), robustness testing, a..."}], "observed_examples": [{"cve": "CVE-2021-41232", "description": "Chain: authentication routine in Go-based agile development product does not escape user name (CWE-116), allowing LDAP injection (CWE-90)"}, {"cve": "CVE-2008-4636", "description": "OS command injection in backup software using shell metacharacters in a filename; correct behavior would require that this filename could not be chang..."}, {"cve": "CVE-2008-0769", "description": "Web application does not set the charset when sending a page to a browser, allowing for XSS exploitation when a browser chooses an unexpected encoding..."}, {"cve": "CVE-2008-0005", "description": "Program does not set the charset when sending a page to a browser, allowing for XSS exploitation when a browser chooses an unexpected encoding."}, {"cve": "CVE-2008-5573", "description": "SQL injection via password parameter; a strong password might contain \"&\""}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "AI/ML", "Database Server", "Web Server"]}}, "1164": {"name": "Irrelevant Code", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product contains code that is not essential for execution,\n\t     i.e. makes no state changes and has no side effects that alter\n\t     data or control flow, such that removal of the code would have no impact\n\t     to functionality or correctness.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Reliability"]}, {"scope": ["Other"], "impact": ["Reduce Performance"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2014-1266", "description": "Chain: incorrect \"goto\" in Apple SSL product bypasses certificate validation, allowing Adversary-in-the-Middle (AITM) attack (Apple \"goto fail\" bug). ..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "117": {"name": "Improper Output Neutralization for Logs", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability", "Non-Repudiation"], "impact": ["Modify Application Data", "Hide Activities", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Use and specify an output encoding that can be handled by the downstream component that is reading the output. Common encodings include ISO-8859-1, UTF-7, and UTF-8. When an encoding is not specified, a downstream component may choose a different encoding, either by assuming a default encoding or au...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2006-4624", "description": "Chain: inject fake log entries with fake timestamps using CRLF injection"}], "platforms": {"languages": ["Not Language-Specific"]}}, "1173": {"name": "Improper Use of Validation Framework", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not use, or incorrectly uses, an input validation framework that is provided by the source language or an independent library.", "extended_description": "Many modern coding languages provide developers with input validation frameworks to make the task of input validation easier and less error-prone. These frameworks will automatically check all input against specified criteria and direct execution to error handlers when invalid input is received. The improper use (i.e., an incorrect implementation or missing altogether) of these frameworks is not directly exploitable, but can lead to an exploitable condition if proper input validation is not perf...", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Properly use provided input validation frameworks.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis"}], "platforms": {"languages": ["Not Language-Specific"]}}, "1174": {"name": "ASP.NET Misconfiguration: Improper Model Validation", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The ASP.NET application does not use, or incorrectly uses, the model validation framework.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "platforms": {"languages": ["ASP.NET"]}}, "1176": {"name": "Inefficient CPU Computation", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product performs CPU computations using\n         algorithms that are not as efficient as they could be for the\n         needs of the developer, i.e., the computations can be\n         optimized further.", "consequences": [{"scope": ["Availability"], "impact": ["Reduce Performance", "DoS: Resource Consumption (CPU)"]}], "observed_examples": [{"cve": "CVE-2022-37734", "description": "Chain: lexer in Java-based GraphQL server does not enforce maximum of tokens early enough (CWE-696), allowing excessive CPU consumption (CWE-1176)"}], "platforms": {"languages": ["Not Language-Specific"]}}, "1177": {"name": "Use of Prohibited Code", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product uses a function, library, or third party component\n\t     that has been explicitly prohibited, whether by the developer or\n\t     the customer.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2007-1470", "description": "Library has multiple buffer overflows using sprintf() and strcpy()"}, {"cve": "CVE-2007-4004", "description": "FTP client uses inherently insecure gets() function and is setuid root on some systems, allowing buffer overflow"}], "platforms": {"languages": ["Not Language-Specific"]}}, "118": {"name": "Incorrect Access of Indexable Resource ('Range Error')", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not restrict or incorrectly restricts operations within the boundaries of a resource that is accessed using an index or pointer, such as memory or files.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1187": {"name": "DEPRECATED: Use of Uninitialized Resource", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "This entry has been deprecated because it was a duplicate of CWE-908. All content has been transferred to CWE-908."}, "1188": {"name": "Initialization of a Resource with an Insecure Default", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-36349", "description": "insecure default variable initialization in BIOS firmware for a hardware board allows DoS"}, {"cve": "CVE-2022-42467", "description": "A generic database browser interface has a default mode that exposes a web server to the network, allowing queries to the database."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1189": {"name": "Improper Isolation of Shared Resources on System-on-a-Chip (SoC)", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The System-On-a-Chip (SoC) does not properly isolate shared resources between trusted and untrusted agents.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Integrity"], "impact": ["Quality Degradation"]}], "detection_methods": [{"method": "Automated Dynamic Analysis"}], "observed_examples": [{"cve": "CVE-2020-8698", "description": "Processor has improper isolation of shared resources allowing for information disclosure."}, {"cve": "CVE-2019-6260", "description": "Baseboard Management Controller (BMC) device implements Advanced High-performance Bus (AHB) bridges that do not require authentication for arbitrary r..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip"]}}, "119": {"name": "Improper Restriction of Operations within the Bounds of a Memory Buffer", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands", "Modify Memory"]}, {"scope": ["Availability", "Confidentiality"], "impact": ["Read Memory", "DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)"]}, {"scope": ["Confidentiality"], "impact": ["Read Memory"]}], "mitigations": [{"description": "Replace unbounded copy functions with analogous functions that support length arguments, such as strcpy with strncpy. Create these if they are not available.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis"}, {"method": "Automated Dynamic Analysis", "description": "This weakness can be detected using dynamic tools and techniques that interact with the software using large test suites with many diverse inputs, such as fuzz testing (fuzzing), robustness testing, a..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2021-22991", "description": "Incorrect URI normalization in application traffic product leads to buffer overflow, as exploited in the wild per CISA KEV."}, {"cve": "CVE-2020-29557", "description": "Buffer overflow in Wi-Fi router web interface, as exploited in the wild per CISA KEV."}, {"cve": "CVE-2009-2550", "description": "Classic stack-based buffer overflow in media player using a long entry in a playlist"}, {"cve": "CVE-2009-2403", "description": "Heap-based buffer overflow in media player using a long entry in a playlist"}, {"cve": "CVE-2009-0689", "description": "large precision value in a format string triggers overflow"}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++", "Assembly"], "technologies": ["Not Technology-Specific"]}}, "1190": {"name": "DMA Device Enabled Too Early in Boot Phase", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product enables a Direct Memory Access (DMA) capable device before the security configuration settings are established, which allows an attacker to extract data from or gain privileges on the product.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Modify Memory"]}], "mitigations": [{"description": "Utilize an IOMMU to orchestrate IO access from\n                 the start of the boot process.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip"]}}, "1191": {"name": "On-Chip Debug and Test Interface With Improper Access Control", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The chip does not implement or does not correctly perform access control to check whether users are authorized to access internal registers and test modes through the physical debug/test interface.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Confidentiality"], "impact": ["Read Memory"]}, {"scope": ["Authorization"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Integrity"], "impact": ["Modify Memory"]}, {"scope": ["Integrity"], "impact": ["Modify Application Data"]}, {"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "If feasible, the manufacturer should disable the JTAG interface or implement authentication and authorization for the JTAG interface. If authentication logic is added, it should be resistant to timing attacks. Security-sensitive data stored in registers, such as keys, etc. should be cleared when ent...", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Dynamic Analysis with Manual Results Interpretation"}, {"method": "Dynamic Analysis with Manual Results Interpretation"}, {"method": "Fuzzing", "description": "Tests that fuzz Debug and Test Interfaces should ensure that no access without appropriate authentication and authorization is possible."}], "observed_examples": [{"cve": "CVE-2019-18827", "description": "chain: JTAG interface is not disabled (CWE-1191) during ROM code execution, introducing a race condition (CWE-362) to extract encryption keys"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1192": {"name": "Improper Identifier for IP Block used in System-On-Chip (SOC)", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The System-on-Chip (SoC) does not have unique, immutable identifiers for each of its components.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip"]}}, "1193": {"name": "Power-On of Untrusted Execution Core Before Enabling Fabric Access Control", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product enables components that contain untrusted firmware before memory and fabric access controls have been enabled.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip"]}}, "12": {"name": "ASP.NET Misconfiguration: Missing Custom Error Page", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "An ASP .NET application must enable custom error pages in order to prevent attackers from mining information from the framework's built-in responses.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Handle exceptions appropriately in source code. ASP .NET applications should be configured to use custom error pages instead of the framework default page.", "phase": ["System Configuration"]}, {"description": "Do not attempt to process an error or attempt to mask it.", "phase": ["Architecture and Design"]}, {"description": "Verify return values are correct and do not supply sensitive information about the system.", "phase": ["Implementation"]}], "platforms": {"languages": ["ASP.NET"]}}, "120": {"name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')", "abstraction": "Base", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Modify Memory", "Execute Unauthorized Code or Commands"]}, {"scope": ["Availability"], "impact": ["Modify Memory", "DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)"]}], "mitigations": [{"description": "For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-s...", "phase": ["Architecture and Design"]}, {"description": "Most mitigating technologies at the compiler or OS level to date address only a subset of buffer overflow problems and rarely provide complete protection against even that subset. It is good practice to implement strategies to increase the workload of an attacker, such as leaving the attacker to gue...", "phase": ["Build and Compilation", "Operation"]}, {"description": "Replace unbounded copy functions with analogous functions that support length arguments, such as strcpy with strncpy. Create these if they are not available.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis"}, {"method": "Automated Dynamic Analysis", "description": "This weakness can be detected using dynamic tools and techniques that interact with the software using large test suites with many diverse inputs, such as fuzz testing (fuzzing), robustness testing, a..."}, {"method": "Manual Analysis", "description": "Manual analysis can be useful for finding this weakness, but it might not achieve desired code coverage within limited time constraints. This becomes difficult for weaknesses that must be considered f..."}], "observed_examples": [{"cve": "CVE-2000-1094", "description": "buffer overflow using command with long argument"}, {"cve": "CVE-1999-0046", "description": "buffer overflow in local program using long environment variable"}, {"cve": "CVE-2002-1337", "description": "buffer overflow in comment characters, when product increments a counter for a \">\" but does not decrement for \"<\""}, {"cve": "CVE-2003-0595", "description": "By replacing a valid cookie value with an extremely long string of characters, an attacker may overflow the application's buffers."}, {"cve": "CVE-2001-0191", "description": "By replacing a valid cookie value with an extremely long string of characters, an attacker may overflow the application's buffers."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++", "Assembly"]}}, "1204": {"name": "Generation of Weak Initialization Vector (IV)", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a cryptographic primitive that uses an Initialization\n\t\t\tVector (IV), but the product does not generate IVs that are\n\t\t\tsufficiently unpredictable or unique according to the expected\n\t\t\tcryptographic requirements for that primitive.", "extended_description": "By design, some cryptographic primitives\n\t\t\t  (such as block ciphers) require that IVs\n\t\t\t  must have certain properties for the\n\t\t\t  uniqueness and/or unpredictability of an\n\t\t\t  IV. Primitives may vary in how important\n\t\t\t  these properties are. If these properties\n\t\t\t  are not maintained, e.g. by a bug in the\n\t\t\t  code, then the cryptography may be weakened\n\t\t\t  or broken by attacking the IVs themselves.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2020-1472", "description": "ZeroLogon vulnerability - use of a static IV of all zeroes in AES-CFB8 mode"}, {"cve": "CVE-2011-3389", "description": "BEAST attack in SSL 3.0 / TLS 1.0. In CBC mode, chained initialization vectors are non-random, allowing decryption of HTTPS traffic using a chosen pla..."}, {"cve": "CVE-2001-0161", "description": "wireless router does not use 6 of the 24 bits for WEP encryption, making it easier for attackers to decrypt traffic"}, {"cve": "CVE-2001-0160", "description": "WEP card generates predictable IV values, making it easier for attackers to decrypt traffic"}, {"cve": "CVE-2017-3225", "description": "device bootloader uses a zero initialization vector during AES-CBC"}], "platforms": {"languages": ["Not Language-Specific"]}}, "1209": {"name": "Failure to Disable Reserved Bits", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The reserved bits in a hardware design are not disabled prior to production. Typically, reserved bits are used for future capabilities and should not support any functional logic in the design.   However, designers might covertly use these bits to debug or further develop new capabilities in production hardware. Adversaries with access to these bits will write to them in hopes of compromising hardware state.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control", "Accountability", "Authentication", "Authorization", "Non-Repudiation"], "impact": ["Varies by Context"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip"]}}, "121": {"name": "Stack-based Buffer Overflow", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Availability"], "impact": ["Modify Memory", "DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)"]}, {"scope": ["Integrity", "Confidentiality", "Availability", "Access Control"], "impact": ["Modify Memory", "Execute Unauthorized Code or Commands", "Bypass Protection Mechanism"]}, {"scope": ["Integrity", "Confidentiality", "Availability", "Access Control", "Other"], "impact": ["Modify Memory", "Execute Unauthorized Code or Commands", "Bypass Protection Mechanism", "Other"]}], "mitigations": [{"description": "Use an abstraction library to abstract away risky APIs. Not a complete solution.", "phase": ["Architecture and Design"]}, {"description": "Implement and perform bounds checking on input.", "phase": ["Implementation"]}, {"description": "Do not use dangerous functions such as gets. Use safer, equivalent functions which check for boundary errors.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2021-35395", "description": "Stack-based buffer overflows in SFK for wifi chipset used for IoT/embedded devices, as exploited in the wild per CISA KEV."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"], "technologies": ["Not Technology-Specific"]}}, "122": {"name": "Heap-based Buffer Overflow", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)"]}, {"scope": ["Integrity", "Confidentiality", "Availability", "Access Control"], "impact": ["Execute Unauthorized Code or Commands", "Bypass Protection Mechanism", "Modify Memory"]}, {"scope": ["Integrity", "Confidentiality", "Availability", "Access Control", "Other"], "impact": ["Execute Unauthorized Code or Commands", "Bypass Protection Mechanism", "Other"]}], "mitigations": [{"description": "Pre-design: Use a language or compiler that performs automatic bounds checking."}, {"description": "Use an abstraction library to abstract away risky APIs. Not a complete solution.", "phase": ["Architecture and Design"]}, {"description": "Implement and perform bounds checking on input.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2025-46687", "description": "Chain: Javascript engine code does not perform a length check (CWE-1284) leading to integer overflow (CWE-190) causing allocation of smaller buffer th..."}, {"cve": "CVE-2021-43537", "description": "Chain: in a web browser, an unsigned 64-bit integer is forcibly cast to a 32-bit integer (CWE-681) and potentially leading to an integer overflow (CWE..."}, {"cve": "CVE-2007-4268", "description": "Chain: integer signedness error (CWE-195) passes signed comparison, leading to heap overflow (CWE-122)"}, {"cve": "CVE-2009-2523", "description": "Chain: product does not handle when an input string is not NULL terminated (CWE-170), leading to buffer over-read (CWE-125) or heap-based buffer overf..."}, {"cve": "CVE-2021-29529", "description": "Chain: machine-learning product can have a heap-based\n\t      buffer overflow (CWE-122) when some integer-oriented bounds are\n\t      calculated by usin..."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"], "technologies": ["Not Technology-Specific"]}}, "1220": {"name": "Insufficient Granularity of Access Control", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Modify Memory", "Read Memory", "Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Other"]}], "observed_examples": [{"cve": "CVE-2022-24985", "description": "A form hosting website only checks the session authentication status for a single form, making it possible to bypass authentication when there are mul..."}, {"cve": "CVE-2021-36934", "description": "An operating system has an overly permission Access Control List onsome system files, including those related to user passwords"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1221": {"name": "Incorrect Register Defaults or Module Parameters", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Hardware description language code incorrectly defines register defaults or hardware Intellectual Property (IP) parameters to insecure values.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "During hardware design, all the system parameters and register defaults must be reviewed to identify security sensitive settings.", "phase": ["Architecture and Design"]}, {"description": "The default values of these security sensitive settings need to be defined as part of the design review phase.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Analysis", "description": "Use automated tools to test that values are configured per design specifications."}], "platforms": {"languages": ["Verilog", "VHDL"], "technologies": ["Not Technology-Specific"]}}, "1222": {"name": "Insufficient Granularity of Address Regions Protected by Register Locks", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product defines a large address region protected from modification by the same register lock control bit. This results in a conflict between the functional requirement that some addresses need to be writable by software during operation and the security requirement that the system configuration lock bit must be set during the boot process.", "consequences": [{"scope": ["Access Control"], "impact": ["Other"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip"]}}, "1223": {"name": "Race Condition for Write-Once Attributes", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A write-once register in hardware design is programmable by an untrusted software component earlier than the trusted software component, resulting in a race condition issue.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "During hardware design, all register write-once or sticky fields must be evaluated for proper configuration.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Analysis", "description": "The testing phase should use automated tools to test that values are not reprogrammable and that write-once fields lock on writing zeros."}], "platforms": {"languages": ["Verilog", "VHDL"], "technologies": ["System on Chip"]}}, "1224": {"name": "Improper Restriction of Write-Once Bit Fields", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The hardware design control register \"sticky bits\" or write-once bit fields are improperly implemented, such that they can be reprogrammed by software.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "During hardware design, all register write-once or sticky fields must be evaluated for proper configuration.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Analysis", "description": "Use automated tools to test that values are not reprogrammable and that write-once fields lock on writing zeros."}], "platforms": {"languages": ["Verilog", "VHDL"], "technologies": ["System on Chip"]}}, "1229": {"name": "Creation of Emergent Resource", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product manages resources or behaves in a way that indirectly creates a new, distinct resource that can be used by attackers in violation of the intended policy.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "123": {"name": "Write-what-where Condition", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability", "Access Control"], "impact": ["Modify Memory", "Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity", "DoS: Crash, Exit, or Restart", "Bypass Protection Mechanism"]}, {"scope": ["Integrity", "Availability"], "impact": ["DoS: Crash, Exit, or Restart", "Modify Memory"]}, {"scope": ["Access Control", "Other"], "impact": ["Bypass Protection Mechanism", "Other"]}], "mitigations": [{"description": "Use a language that provides appropriate memory abstractions.", "phase": ["Architecture and Design"]}, {"description": "Use OS-level preventative functionality integrated after the fact. Not a complete solution.", "phase": ["Operation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2019-19911", "description": "Chain: Python library does not limit the resources used to process images that specify a very large number of bands (CWE-1284), leading to excessive m..."}, {"cve": "CVE-2022-0545", "description": "Chain: 3D renderer has an integer overflow (CWE-190) leading to write-what-where condition (CWE-123) using a crafted image."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "1230": {"name": "Exposure of Sensitive Information Through Metadata", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product prevents direct access to a resource containing sensitive information, but it does not sufficiently limit access to metadata that is derived from the original, sensitive information.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1231": {"name": "Improper Prevention of Lock Bit Modification", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a trusted lock bit for restricting access to registers, address regions, or other resources, but the product does not prevent the value of the lock bit from being modified after it has been set.", "consequences": [{"scope": ["Access Control"], "impact": ["Modify Memory"]}], "detection_methods": [{"method": "Manual Analysis", "description": "Set the lock bit. Power cycle the\n\t     device. Attempt to clear the lock bit.  If the\n\t     information is changed, implement a design\n\t     fix. Retest. Also, attempt to indirectly clear the lock\n\t ..."}], "observed_examples": [{"cve": "CVE-2017-6283", "description": "chip reset clears critical read/write lock permissions for RSA function"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1232": {"name": "Improper Lock Behavior After Power State Transition", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Register lock bit protection disables changes to system configuration once the bit is set. Some of the protected registers or lock bits become programmable after power state transitions (e.g., Entry and wake from low power sleep modes) causing the system configuration to be changeable.", "consequences": [{"scope": ["Access Control"], "impact": ["Modify Memory"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1233": {"name": "Security-Sensitive Hardware Controls with Missing Lock Bit Protection", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a register lock bit protection mechanism, but it does not ensure that the lock bit prevents modification of system registers or controls that perform changes to important hardware system configuration.", "consequences": [{"scope": ["Access Control"], "impact": ["Modify Memory"]}], "detection_methods": [{"method": "Manual Analysis", "description": "Set the lock bit. Attempt to modify the\n\t     information protected by the lock bit. If the information\n\t     is changed, implement a design fix. Retest. Also, attempt\n\t     to indirectly clear the lo..."}], "observed_examples": [{"cve": "CVE-2018-9085", "description": "Certain servers leave a write protection lock bit\n\t\tunset after boot, potentially allowing modification of\n\t\tparts of flash memory."}, {"cve": "CVE-2014-8273", "description": "Chain: chipset has a race condition (CWE-362) between when an interrupt handler detects an attempt to write-enable the BIOS (in violation of the lock ..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1234": {"name": "Hardware Internal or Debug Modes Allow Override of Locks", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "System configuration protection may be bypassed during debug mode.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1235": {"name": "Incorrect Use of Autoboxing and Unboxing for Performance Critical Operations", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The code uses boxed primitives, which may introduce inefficiencies into performance-critical operations.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Resource Consumption (Other)", "Reduce Performance"]}], "mitigations": [{"description": "Use of boxed primitives should be limited to certain situations such as when calling methods with typed parameters.  They should not be used for scientific computing or other performance critical operations. They are only suited to support \"impedance mismatch\" between reference types and primitives....", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java", "C#"], "technologies": ["Not Technology-Specific"]}}, "1236": {"name": "Improper Neutralization of Formula Elements in a CSV File", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "When generating CSV output, ensure that formula-sensitive metacharacters are effectively escaped or removed from all data before storage in the resultant CSV.  Risky characters include '=' (equal), '+' (plus), '-' (minus), and '@' (at).", "phase": ["Implementation"]}, {"description": "If a field starts with a formula character, prepend it with a ' (single apostrophe), which prevents Excel from executing the formula.", "phase": ["Implementation"]}, {"description": "Certain implementations of spreadsheet software might disallow formulas from executing if the file is untrusted, or if the file is not authored by the current user.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2019-12134", "description": "Low privileged user can trigger CSV injection through a contact form field value"}, {"cve": "CVE-2019-4521", "description": "Cloud management product allows arbitrary command execution via CSV injection"}, {"cve": "CVE-2019-17661", "description": "CSV injection in content management system via formula code in a first or last name"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Other"]}}, "1239": {"name": "Improper Zeroization of Hardware Register", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The hardware product does not properly clear sensitive information from built-in registers when the user of the hardware block changes.", "extended_description": "Hardware logic operates on data stored in registers local to the hardware block. Most hardware IPs, including cryptographic accelerators, rely on registers to buffer I/O, store intermediate values, and interface with software. The result of this is that sensitive information, such as passwords or encryption keys, can exist in locations not transparent to the user of the hardware logic. When a different entity obtains access to the IP due to a change in operating mode or conditions, the new entit...", "consequences": [{"scope": ["Confidentiality"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Every register potentially containing sensitive information must have a policy specifying how and when information is cleared, in addition to clarifying if it is the responsibility of the hardware logic or IP user to initiate the zeroization procedure at the appropriate time.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip"]}}, "124": {"name": "Buffer Underwrite ('Buffer Underflow')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Integrity", "Availability"], "impact": ["Modify Memory", "DoS: Crash, Exit, or Restart"]}, {"scope": ["Integrity", "Confidentiality", "Availability", "Access Control", "Other"], "impact": ["Execute Unauthorized Code or Commands", "Modify Memory", "Bypass Protection Mechanism", "Other"]}, {"scope": ["Access Control", "Other"], "impact": ["Bypass Protection Mechanism", "Other"]}], "mitigations": [{"description": "Choose a language that is not susceptible to these issues.", "phase": ["Requirements"]}, {"description": "All calculated values that are used as index or for pointer arithmetic should be validated to ensure that they are within an expected range.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2021-24018", "description": "buffer underwrite in firmware verification routine allows code execution via a crafted firmware image"}, {"cve": "CVE-2002-2227", "description": "Unchecked length of SSLv2 challenge value leads to buffer underflow."}, {"cve": "CVE-2007-4580", "description": "Buffer underflow from a small size value with a large buffer (length parameter inconsistency, CWE-130)"}, {"cve": "CVE-2007-1584", "description": "Buffer underflow from an all-whitespace string, which causes a counter to be decremented before the buffer while looking for a non-whitespace characte..."}, {"cve": "CVE-2007-0886", "description": "Buffer underflow resultant from encoded data that triggers an integer overflow."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "1240": {"name": "Use of a Cryptographic Primitive with a Risky Implementation", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "To fulfill the need for a cryptographic primitive, the product implements a cryptographic algorithm using a non-standard, unproven, or disallowed/non-compliant cryptographic implementation.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Require compliance with the strongest-available recommendations from trusted parties, and require that compliance must be kept up-to-date, since recommendations evolve over time. For example, US government systems require FIPS 140-3 certification, which supersedes FIPS 140-2 [REF-1192] [REF-267].", "phase": ["Requirements"]}, {"description": "Ensure that the architecture/design uses the strongest-available primitives and algorithms from trusted parties. For example, US government systems require FIPS 140-3 certification, which supersedes FIPS 140-2 [REF-1192] [REF-267].", "phase": ["Architecture and Design"]}, {"description": "Do not develop custom or private cryptographic algorithms. They will likely be exposed to attacks that are well-understood by cryptographers. As with all cryptographic mechanisms, the source code should be available for analysis. If the algorithm may be compromised when attackers find out how it wor...", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Architecture or Design Review", "description": "Review requirements, documentation, and product design to ensure that primitives are consistent with the strongest-available recommendations from trusted parties. If the product appears to be using cu..."}, {"method": "Manual Analysis", "description": "Analyze the product to ensure that implementations for each primitive do not contain any known vulnerabilities and are not using any known-weak algorithms, including MD4, MD5, SHA1, DES, etc."}, {"method": "Dynamic Analysis with Manual Results Interpretation", "description": "For hardware, during the implementation (pre-Silicon / post-Silicon) phase, dynamic tests should be done to ensure that outputs from cryptographic routines are indeed working properly, such as test ve..."}], "observed_examples": [{"cve": "CVE-2020-4778", "description": "software uses MD5, which is less safe than the default SHA-256 used by related products"}, {"cve": "CVE-2005-2946", "description": "Default configuration of product uses MD5 instead of stronger algorithms that are available, simplifying forgery of certificates."}, {"cve": "CVE-2019-3907", "description": "identity card uses MD5 hash of a salt and password"}, {"cve": "CVE-2021-34687", "description": "personal key is transmitted over the network using a substitution cipher"}, {"cve": "CVE-2020-14254", "description": "product does not disable TLS-RSA cipher suites, allowing decryption of traffic if TLS 2.0 and secure ciphers are not enabled."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip"]}}, "1241": {"name": "Use of Predictable Algorithm in Random Number Generator", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The device uses an algorithm that is predictable and generates a pseudo-random number.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "It is highly recommended to use a true random number generator (TRNG) to ensure the security of encryption schemes. Hardware-based TRNGs generate unpredictable, unbiased, and independent random numbers because they employ physical phenomena, e.g., electrical noise, as sources to generate random numb...", "phase": ["Architecture and Design"]}, {"description": "It is highly recommended to use a true random number generator (TRNG) to ensure the security of encryption schemes. Hardware-based TRNGs generate unpredictable, unbiased, and independent random numbers because they employ physical phenomena, e.g., electrical noise, as sources to generate random numb...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2021-3692", "description": "PHP framework uses mt_rand() function (Marsenne Twister) when generating tokens"}], "platforms": {"technologies": ["System on Chip"]}}, "1242": {"name": "Inclusion of Undocumented Features or Chicken Bits", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The device includes chicken bits or undocumented features that can create entry points for unauthorized actors.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Modify Memory", "Read Memory", "Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity", "Bypass Protection Mechanism"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "ICS/OT"]}}, "1243": {"name": "Sensitive Non-Volatile Information Not Protected During Debug", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Access to security-sensitive information stored in fuses is not limited during debug.", "consequences": [{"scope": ["Confidentiality", "Access Control"], "impact": ["Modify Memory", "Read Memory", "Bypass Protection Mechanism"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1244": {"name": "Internal Asset Exposed to Unsafe Debug Access Level or State", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses physical debug or test\n        interfaces with support for multiple access levels, but it\n        assigns the wrong debug access level to an internal asset,\n        providing unintended access to the asset from untrusted debug\n        agents.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}, {"scope": ["Integrity"], "impact": ["Modify Memory"]}, {"scope": ["Authorization", "Access Control"], "impact": ["Gain Privileges or Assume Identity", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Apply blinding [REF-1219] or masking techniques in strategic areas.", "phase": ["Architecture and Design"]}, {"description": "Add shielding or tamper-resistant protections to the device, which increases the difficulty and cost for accessing debug/test interfaces.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Manual Analysis", "description": "Check 2 devices for their passcode to authenticate access to JTAG/debugging ports. If the passcodes are missing or the same, update the design to fix and retest. Check communications over JTAG/debuggi..."}], "observed_examples": [{"cve": "CVE-2019-18827", "description": "After ROM code execution, JTAG access is disabled. But before the ROM code is executed, JTAG access is possible, allowing a user full system access.  ..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip"]}}, "1245": {"name": "Improper Finite State Machines (FSMs) in Hardware Logic", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Faulty finite state machines (FSMs) in the hardware logic allow an attacker to put the system in an undefined state, to cause a denial of service (DoS) or gain privileges on the victim's system.", "consequences": [{"scope": ["Availability", "Access Control"], "impact": ["Unexpected State", "DoS: Crash, Exit, or Restart", "DoS: Instability", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Define all possible states and handle all unused states through default statements. Ensure that system defaults to a secure state.", "phase": ["Architecture and Design", "Implementation"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip"]}}, "1246": {"name": "Improper Write Handling in Limited-write Non-Volatile Memories", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not implement or incorrectly implements wear leveling operations in limited-write non-volatile memories.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Instability"]}], "mitigations": [{"description": "Include secure wear leveling algorithms and ensure they may not be bypassed.", "phase": ["Architecture and Design", "Implementation", "Testing"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip", "Memory Hardware", "Storage Hardware"]}}, "1247": {"name": "Improper Protection Against Voltage and Clock Glitches", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The device does not contain or contains incorrectly implemented circuitry or sensors to detect and mitigate voltage and clock glitches and protect sensitive information or software contained on the device.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Read Memory", "Modify Memory", "Execute Unauthorized Code or Commands"]}], "detection_methods": [{"method": "Manual Analysis"}, {"method": "Dynamic Analysis with Manual Results Interpretation", "description": "During the implementation phase where actual hardware is available, specialized hardware tools and apparatus such as ChipWhisperer may be used to check if the platform is indeed susceptible to voltage..."}, {"method": "Architecture or Design Review", "description": "Review if the protections against glitching merely transfer the attack target. For example, suppose a critical authentication routine that an attacker would want to bypass is given the protection of m..."}], "observed_examples": [{"cve": "CVE-2019-17391", "description": "Lack of anti-glitch protections allows an attacker to launch a physical attack to bypass the secure boot and read protected eFuses."}, {"cve": "CVE-2021-33478", "description": "IP communication firmware allows access to a boot shell via certain impulses"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["ICS/OT", "System on Chip", "Power Management Hardware", "Clock/Counter Hardware", "Sensor Hardware"]}}, "1248": {"name": "Semiconductor Defects in Hardware Logic with Security-Sensitive Implications", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The security-sensitive hardware module contains semiconductor defects.", "consequences": [{"scope": ["Availability", "Access Control"], "impact": ["DoS: Instability"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1249": {"name": "Application-Level Admin Tool with Inconsistent View of Underlying Operating System", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product provides an application for administrators to manage parts of the underlying operating system, but the application does not accurately identify all of the relevant entities or resources that exist in the OS; that is, the application's model of the OS's state is inconsistent with the OS's actual state.", "consequences": [{"scope": ["Access Control"], "impact": ["Varies by Context"]}, {"scope": ["Accountability"], "impact": ["Hide Activities"]}, {"scope": ["Other"], "impact": ["Unexpected State"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based"]}}, "125": {"name": "Out-of-bounds Read", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product reads data past the end, or before the beginning, of the intended buffer.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}, {"scope": ["Confidentiality"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Use a language that provides appropriate memory abstractions.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2023-1018", "description": "The reference implementation code for a Trusted Platform Module does not implement length checks on data, allowing for an attacker to read 2 bytes pas..."}, {"cve": "CVE-2020-11899", "description": "Out-of-bounds read in IP stack used in embedded systems, as exploited in the wild per CISA KEV."}, {"cve": "CVE-2014-0160", "description": "Chain: \"Heartbleed\" bug receives an inconsistent length parameter (CWE-130) enabling an out-of-bounds read (CWE-126), returning memory that could incl..."}, {"cve": "CVE-2021-40985", "description": "HTML conversion package has a buffer under-read, allowing a crash"}, {"cve": "CVE-2018-10887", "description": "Chain: unexpected sign extension (CWE-194) leads to integer overflow (CWE-190), causing an out-of-bounds read (CWE-125)"}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"], "technologies": ["ICS/OT"]}}, "1250": {"name": "Improper Preservation of Consistency Between Independent Representations of Shared State", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product has or supports multiple distributed components or sub-systems that are each required to keep their own local copy of shared data - such as state or cache - but the product does not ensure that all local copies remain consistent with each other.", "consequences": [{"scope": ["Other"], "impact": ["Unexpected State"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Cloud Computing", "Security Hardware"]}}, "1251": {"name": "Mirrored Regions with Different Values", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product's architecture mirrors regions without ensuring that their contents always stay in sync.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control", "Accountability", "Authentication", "Authorization", "Non-Repudiation"], "impact": ["Varies by Context"]}], "platforms": {"languages": ["VHDL", "Verilog"], "technologies": ["System on Chip"]}}, "1252": {"name": "CPU Hardware Not Configured to Support Exclusivity of Write and Execute Operations", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The CPU is not configured to provide hardware support for exclusivity of write and execute operations on memory. This allows an attacker to execute data from all of memory.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Execute Unauthorized Code or Commands"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Microcontroller Hardware", "Processor Hardware"]}}, "1253": {"name": "Incorrect Selection of Fuse Values", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The logic level used to set a system to a secure state relies on a fuse being unblown.", "consequences": [{"scope": ["Access Control", "Authorization"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Confidentiality"], "impact": ["Read Memory"]}, {"scope": ["Integrity"], "impact": ["Modify Memory", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Logic should be designed in a way that blown fuses do not put the product into an insecure state that can be leveraged by an attacker.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1254": {"name": "Incorrect Comparison Logic Granularity", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product's comparison logic is performed over a series of steps rather than across the entire string in one operation. If there is a comparison logic failure on one of these steps, the operation may be vulnerable to a timing attack that can result in the interception of the process for nefarious purposes.", "consequences": [{"scope": ["Confidentiality", "Authorization"], "impact": ["Bypass Protection Mechanism"]}], "observed_examples": [{"cve": "CVE-2019-10482", "description": "Smartphone OS uses comparison functions that are not in constant time, allowing side channels"}, {"cve": "CVE-2019-10071", "description": "Java-oriented framework compares HMAC signatures  using  String.equals() instead of a constant-time algorithm, causing timing discrepancies"}, {"cve": "CVE-2014-0984", "description": "Password-checking function in router terminates validation of a password entry when it encounters the first incorrect character, which allows remote a..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1255": {"name": "Comparison Logic is Vulnerable to Power Side-Channel Attacks", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "A device's real time power consumption may be monitored during security token evaluation and the information gleaned may be used to determine the value of the reference token.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control", "Accountability", "Authentication", "Authorization", "Non-Repudiation"], "impact": ["Modify Memory", "Read Memory", "Read Files or Directories", "Modify Files or Directories", "Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Read Application Data", "Modify Application Data", "Hide Activities"]}], "mitigations": [{"description": "The design phase must consider each check of a security token against a standard and the amount of power consumed during the check of a good token versus a bad token. The alternative is an all at once check where a retry counter is incremented PRIOR to the check.", "phase": ["Architecture and Design"]}, {"description": "Another potential mitigation is to parallelize shifting of secret data (see example 2 below). Note that the wider the bus the more effective the result.", "phase": ["Architecture and Design"]}, {"description": "An additional potential mitigation is to add random data to each crypto operation then subtract it out afterwards. This is highly effective but costly in performance, area, and power consumption. It also requires a random number generator.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2020-12788", "description": "CMAC verification vulnerable to timing and power attacks."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1256": {"name": "Improper Restriction of Software Interfaces to Hardware Features", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product provides software-controllable\n\t\t\tdevice functionality for capabilities such as power and\n\t\t\tclock management, but it does not properly limit\n\t\t\tfunctionality that can lead to modification of\n\t\t\thardware memory or register bits, or the ability to\n\t\t\tobserve physical side channels.", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Memory", "Modify Application Data", "Bypass Protection Mechanism"]}], "detection_methods": [{"method": "Manual Analysis", "description": "Perform a security evaluation of system-level\n\t\tarchitecture and design with software-aided physical attacks\n\t\tin scope."}, {"method": "Automated Dynamic Analysis"}], "observed_examples": [{"cve": "CVE-2019-11157", "description": "Plundervolt: Improper conditions check in voltage settings for some Intel(R) Processors may allow a privileged user to potentially enable escalation o..."}, {"cve": "CVE-2020-8694", "description": "PLATYPUS Attack: Insufficient access control in the Linux kernel driver for some Intel processors allows information disclosure."}, {"cve": "CVE-2020-8695", "description": "Observable discrepancy in the RAPL interface for some Intel processors allows information disclosure."}, {"cve": "CVE-2020-12912", "description": "AMD extension to a Linux service does not require privileged access to the RAPL interface, allowing side-channel attacks."}, {"cve": "CVE-2015-0565", "description": "NaCl in 2015 allowed the CLFLUSH instruction, making Rowhammer attacks possible."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Memory Hardware", "Power Management Hardware", "Clock/Counter Hardware"]}}, "1257": {"name": "Improper Access Control Applied to Mirrored or Aliased Memory Regions", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Aliased or mirrored memory regions in hardware designs may have inconsistent read/write permissions enforced by the hardware. A possible result is that an untrusted agent is blocked from accessing a memory region but is not blocked from accessing the corresponding aliased memory region.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}, {"scope": ["Integrity"], "impact": ["Modify Memory"]}, {"scope": ["Availability"], "impact": ["DoS: Instability"]}], "mitigations": [{"description": "The checks should be applied for consistency access rights between primary memory regions and any mirrored or aliased memory regions. If different memory protection units (MPU) are protecting the aliased regions, their protected range definitions and policies should be synchronized.", "phase": ["Architecture and Design", "Implementation"]}, {"description": "The controls that allow enabling memory aliases or changing the size of mapped memory regions should only be programmable by trusted software components.", "phase": ["Architecture and Design", "Implementation"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Memory Hardware", "Processor Hardware", "Microcontroller Hardware", "Network on Chip Hardware", "System on Chip"]}}, "1258": {"name": "Exposure of Sensitive System Information Due to Uncleared Debug Information", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The hardware does not fully clear security-sensitive values, such as keys and intermediate values in cryptographic operations, when debug mode is entered.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}, {"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "observed_examples": [{"cve": "CVE-2021-33080", "description": "Uncleared debug information in memory accelerator for SSD product exposes sensitive system information"}, {"cve": "CVE-2022-31162", "description": "Rust library leaks Oauth client details in application debug logs"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1259": {"name": "Improper Restriction of Security Token Assignment", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The System-On-A-Chip (SoC) implements a Security Token mechanism to differentiate what actions are allowed or disallowed when a transaction originates from an entity. However, the Security Tokens are improperly protected.", "extended_description": "Systems-On-A-Chip (Integrated circuits and hardware engines) implement Security Tokens to differentiate and identify which actions originated from which agent. These actions may be one of the directives: 'read', 'write', 'program', 'reset', 'fetch', 'compute', etc. Security Tokens are assigned to every agent in the System that is capable of generating an action or receiving an action from another agent. Multiple Security Tokens may be assigned to an agent and may be unique based on the agent's t...", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Modify Files or Directories", "Execute Unauthorized Code or Commands", "Bypass Protection Mechanism", "Gain Privileges or Assume Identity", "Modify Memory", "Modify Memory", "DoS: Crash, Exit, or Restart"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Processor Hardware", "System on Chip"]}}, "126": {"name": "Buffer Over-read", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}, {"scope": ["Confidentiality"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Availability", "Integrity"], "impact": ["DoS: Crash, Exit, or Restart"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2022-1733", "description": "Text editor has out-of-bounds read past end of line while indenting C code"}, {"cve": "CVE-2014-0160", "description": "Chain: \"Heartbleed\" bug receives an inconsistent length parameter (CWE-130) enabling an out-of-bounds read (CWE-126), returning memory that could incl..."}, {"cve": "CVE-2009-2523", "description": "Chain: product does not handle when an input string is not NULL terminated, leading to buffer over-read or heap-based buffer overflow."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "1260": {"name": "Improper Handling of Overlap Between Protected Memory Ranges", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product allows address regions to overlap, which can result in the bypassing of intended memory protection.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Modify Memory", "Read Memory", "DoS: Instability"]}], "detection_methods": [{"method": "Manual Analysis", "description": "Create a high privilege memory block of any arbitrary size. Attempt to create a lower privilege memory block with an overlap of the high privilege memory block. If the creation attempt works, fix the ..."}], "observed_examples": [{"cve": "CVE-2008-7096", "description": "virtualization product allows compromise of hardware product by accessing certain remapping registers."}, {"cve": "[REF-1100]", "description": "processor design flaw allows ring 0 code to access more privileged rings by causing a register window to overlap a range of protected system RAM [REF-..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Memory Hardware", "Processor Hardware"]}}, "1261": {"name": "Improper Handling of Single Event Upsets", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The hardware logic does not effectively handle when single-event upsets (SEUs) occur.", "consequences": [{"scope": ["Availability", "Access Control"], "impact": ["DoS: Crash, Exit, or Restart", "DoS: Instability", "Gain Privileges or Assume Identity", "Bypass Protection Mechanism"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1262": {"name": "Improper Access Control for Register Interface", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses memory-mapped I/O registers that act as an interface to hardware functionality from software, but there is improper access control to those registers.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Memory", "Read Application Data", "Modify Memory", "Modify Application Data", "Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Unexpected State", "Alter Execution Logic"]}], "mitigations": [{"description": "Design proper policies for hardware register access from software.", "phase": ["Architecture and Design"]}, {"description": "Ensure that access control policies for register access are implemented in accordance with the specified design.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Manual Analysis", "description": "This is applicable in the Architecture phase before implementation started. Make sure access policy is specified for the entire memory map. Manual analysis may not ensure the implementation is correct..."}, {"method": "Manual Analysis", "description": "Registers controlling hardware should have access control implemented. This access control may be checked manually for correct implementation. Items to check consist of how are trusted parties set, ho..."}, {"method": "Simulation / Emulation", "description": "Functional simulation is applicable during the Implementation Phase. Testcases must be created and executed for memory mapped registers to verify adherence to the access control policy. This method ca..."}], "observed_examples": [{"cve": "CVE-2014-2915", "description": "virtualization product does not restrict access to debug and other processor registers in the hardware, allowing a crash of the host or guest OS"}, {"cve": "CVE-2021-3011", "description": "virtual interrupt controller in a virtualization product allows crash of host by writing a certain invalid value to a register, which triggers a fatal..."}, {"cve": "CVE-2020-12446", "description": "Driver exposes access to Model Specific Register (MSR) registers, allowing admin privileges."}, {"cve": "CVE-2015-2150", "description": "Virtualization product does not restrict access to PCI command registers, allowing host crash from the guest."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1263": {"name": "Improper Physical Access Control", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product is designed with access restricted to certain information, but it does not sufficiently protect against an unauthorized actor with physical access to these areas.", "extended_description": "Sections of a product intended to have restricted access may be inadvertently or intentionally rendered accessible when the implemented physical protections are insufficient. The specific requirements around how robust the design of the physical protection mechanism needs to be depends on the type of product being protected. Selecting the correct physical protection mechanism and properly enforcing it through implementation and manufacturing are critical to the overall physical security of the p...", "consequences": [{"scope": ["Confidentiality", "Integrity", "Access Control"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Specific protection requirements depend strongly on contextual factors including the level of acceptable risk associated with compromise to the product's protection mechanism. Designers could incorporate anti-tampering measures that protect against or detect when the product has been tampered with.", "phase": ["Architecture and Design"]}, {"description": "The testing phase of the lifecycle should establish a method for determining whether the protection mechanism is sufficient to prevent unauthorized access.", "phase": ["Testing"]}, {"description": "Ensure that all protection mechanisms are fully activated at the time of manufacturing and distribution.", "phase": ["Manufacturing"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1264": {"name": "Hardware Logic with Insecure De-Synchronization between Control and Data Channels", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The hardware logic for error handling and security checks can incorrectly forward data before the security check is complete.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory", "Read Application Data"]}], "observed_examples": [{"cve": "CVE-2017-5754", "description": "Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an att..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1265": {"name": "Unintended Reentrant Invocation of Non-reentrant Code Via Nested Calls", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product invokes code that is believed to be reentrant, but the code performs a call that unintentionally produces a nested invocation of the non-reentrant code.", "extended_description": "In a complex product, a single function call may lead to many different possible code paths, some of which may involve deeply nested calls. It may be difficult to foresee all possible code paths that could emanate from a given function call, even if that call is assumed to be reentrant. In some systems, an external actor can manipulate inputs to the system and thereby achieve a wide range of possible control flows. This is frequently a concern in products that execute scripts from untrusted sour...", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "When architecting a system that will execute untrusted code in response to events, consider executing the untrusted event handlers asynchronously (asynchronous message passing) as opposed to executing them synchronously at the time each event fires. The untrusted code should execute at the start of ...", "phase": ["Architecture and Design"]}, {"description": "Make sure the code (e.g., function or class) in question is reentrant by not leveraging non-local data, not modifying its own code, and not calling other non-reentrant code.", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2014-1772", "description": "In this vulnerability, by registering a malicious onerror handler, an adversary can produce unexpected re-entrance of a CDOMRange object. [REF-1098]"}, {"cve": "CVE-2018-8174", "description": "This CVE covers several vulnerable scenarios enabled by abuse of the Class_Terminate feature in Microsoft VBScript. In one scenario, Class_Terminate i..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1266": {"name": "Improper Scrubbing of Sensitive Data from Decommissioned Device", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly provide a capability for the product administrator to remove sensitive data at the time the product is decommissioned.  A scrubbing capability could be missing, insufficient, or incorrect.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1267": {"name": "Policy Uses Obsolete Encoding", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses an obsolete encoding mechanism to implement access controls.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Modify Memory", "Read Memory", "Modify Files or Directories", "Read Files or Directories", "DoS: Resource Consumption (Other)", "Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Reduce Reliability"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1268": {"name": "Policy Privileges are not Assigned Consistently Between Control and Data Agents", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product's hardware-enforced access control for a particular resource improperly accounts for privilege discrepancies between control and write policies.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Modify Memory", "Read Memory", "DoS: Crash, Exit, or Restart", "Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Read Files or Directories", "Reduce Reliability"]}], "mitigations": [{"description": "Access-control-policy definition and programming flow must be sufficiently tested in pre-silicon and post-silicon testing.", "phase": ["Architecture and Design", "Implementation"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1269": {"name": "Product Released in Non-Release Configuration", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product released to market is released in pre-production or manufacturing configuration.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control", "Accountability", "Authentication", "Authorization", "Non-Repudiation"], "impact": ["Other"]}], "mitigations": [{"description": "Ensure that there exists a marker for denoting the Manufacturing Complete stage and that the Manufacturing Complete marker gets updated at the Manufacturing Complete stage (i.e., the Manufacturing Complete fuse gets blown).", "phase": ["Implementation"]}, {"description": "Ensure that there exists a marker for denoting the Manufacturing Complete stage and that the Manufacturing Complete marker gets updated at the Manufacturing Complete stage (i.e., the Manufacturing Complete fuse gets blown).", "phase": ["Integration"]}, {"description": "Ensure that there exists a marker for denoting the Manufacturing Complete stage and that the Manufacturing Complete marker gets updated at the Manufacturing Complete stage (i.e., the Manufacturing Complete fuse gets blown).", "phase": ["Manufacturing"]}], "observed_examples": [{"cve": "CVE-2019-13945", "description": "Regarding SSA-686531, a hardware based manufacturing access on S7-1200 and\nS7-200 SMART has occurred. A vulnerability has been identified in SIMATIC S..."}, {"cve": "CVE-2018-4251", "description": "Laptops with Intel chipsets were found to be running in Manufacturing Mode. After this information was reported to the OEM, the vulnerability (CVE-201..."}], "platforms": {"languages": ["VHDL", "Verilog", "Compiled"], "technologies": ["Other", "Not Technology-Specific"]}}, "127": {"name": "Buffer Under-read", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations prior to the targeted buffer.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}, {"scope": ["Confidentiality"], "impact": ["Bypass Protection Mechanism"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2021-40985", "description": "HTML conversion package has a buffer under-read, allowing a crash"}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "1270": {"name": "Generation of Incorrect Security Tokens", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product implements a Security Token mechanism to differentiate what actions are allowed or disallowed when a transaction originates from an entity. However, the Security Tokens generated in the system are incorrect.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Modify Files or Directories", "Execute Unauthorized Code or Commands", "Bypass Protection Mechanism", "Gain Privileges or Assume Identity", "Read Memory", "Modify Memory", "DoS: Crash, Exit, or Restart"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1271": {"name": "Uninitialized Value on Reset for Registers Holding Security Settings", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Security-critical logic is not set to a known value on reset.", "consequences": [{"scope": ["Access Control", "Authentication", "Authorization"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Design checks should be performed to identify any uninitialized flip-flops used for security-critical functions.", "phase": ["Implementation"]}, {"description": "All registers holding security-critical information should be set to a specific value on reset.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1272": {"name": "Sensitive Information Uncleared Before Debug/Power State Transition", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product performs a power or debug state transition, but it does not clear sensitive information that should no longer be accessible due to changes to information access restrictions.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control", "Accountability", "Authentication", "Authorization", "Non-Repudiation"], "impact": ["Read Memory", "Read Application Data"]}], "mitigations": [{"description": "During state transitions, information not needed in the next state should be removed before the transition to the next state.", "phase": ["Architecture and Design", "Implementation"]}], "detection_methods": [{"method": "Manual Analysis", "description": "Write a known pattern into each sensitive location. Enter the power/debug state in question. Read data back from the sensitive locations. If the reads are successful, and the data is the same as the p..."}], "observed_examples": [{"cve": "CVE-2020-12926", "description": "Product software does not set a flag as per TPM specifications, thereby preventing a failed authorization attempt from being recorded after a loss of ..."}], "platforms": {"languages": ["VHDL", "Verilog", "Hardware Description Language"], "technologies": ["Not Technology-Specific"]}}, "1273": {"name": "Device Unlock Credential Sharing", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The credentials necessary for unlocking a device are shared across multiple parties and may expose sensitive information.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control", "Accountability", "Authentication", "Authorization", "Non-Repudiation"], "impact": ["Modify Memory", "Read Memory", "Modify Files or Directories", "Read Files or Directories", "Modify Application Data", "Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Ensure the unlock credentials are shared with the minimum number of parties and with utmost secrecy. To limit the risk associated with compromised credentials, where possible, the credentials should be part-specific.", "phase": ["Integration"]}, {"description": "Ensure the unlock credentials are shared with the minimum number of parties and with utmost secrecy. To limit the risk associated with compromised credentials, where possible, the credentials should be part-specific.", "phase": ["Manufacturing"]}], "platforms": {"languages": ["VHDL", "Verilog", "Compiled"], "technologies": ["Other", "Not Technology-Specific"]}}, "1274": {"name": "Improper Access Control for Volatile Memory Containing Boot Code", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product conducts a secure-boot process that transfers bootloader code from Non-Volatile Memory (NVM) into Volatile Memory (VM), but it does not have sufficient access control or other protections for the Volatile Memory.", "consequences": [{"scope": ["Access Control", "Integrity"], "impact": ["Modify Memory", "Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Ensure that the design of volatile-memory protections is enough to prevent modification from an adversary or untrusted code.", "phase": ["Architecture and Design"]}, {"description": "Test the volatile-memory protections to ensure they are safe from modification or untrusted code.", "phase": ["Testing"]}], "detection_methods": [{"method": "Manual Analysis", "description": "Ensure the volatile memory is lockable or has locks. Ensure the volatile memory is locked for writes from untrusted agents or adversaries. Try modifying the volatile memory from an untrusted agent, an..."}, {"method": "Manual Analysis"}], "observed_examples": [{"cve": "CVE-2019-2267", "description": "Locked memory regions may be modified through other interfaces in a secure-boot-loader image due to improper access control."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1275": {"name": "Sensitive Cookie with Improper SameSite Attribute", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The SameSite attribute for sensitive cookies is not set, or an insecure value is used.", "extended_description": "The SameSite attribute controls how cookies are sent for cross-domain requests. This attribute may have three values: 'Lax', 'Strict', or 'None'. If the 'None' value is used, a website may create a cross-domain POST HTTP request to another website, and the browser automatically adds cookies to this request. This may lead to Cross-Site-Request-Forgery (CSRF) attacks if there are no additional protections in place (such as Anti-CSRF tokens).", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality", "Integrity", "Non-Repudiation", "Access Control"], "impact": ["Modify Application Data"]}], "mitigations": [{"description": "Set the SameSite attribute of a sensitive cookie to 'Lax' or 'Strict'. This instructs the browser to apply this cookie only to same-domain requests, which provides a good Defense in Depth against CSRF attacks. When the 'Lax' value is in use, cookies are also sent for top-level cross-domain navigatio...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-24045", "description": "Web application for a room automation system has client-side JavaScript that sets a sensitive cookie without the SameSite security attribute, allowing..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "1276": {"name": "Hardware Child Block Incorrectly Connected to Parent System", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Signals between a hardware IP and the parent system design are incorrectly connected causing security risks.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "System-level verification may be used to ensure that components are correctly connected and that design security requirements are not violated due to interactions between various IP blocks.", "phase": ["Testing"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1277": {"name": "Firmware Not Updateable", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not provide its\n\t\t\tusers with the ability to update or patch its\n\t\t\tfirmware to address any vulnerabilities or\n\t\t\tweaknesses that may be present.", "extended_description": "Without the ability to\n\t\t\tpatch or update firmware, consumers will be\n\t\t\tleft vulnerable to exploitation of any known\n\t\t\tvulnerabilities, or any vulnerabilities that\n\t\t\tare discovered in the future. This can expose\n\t\t\tconsumers to permanent risk throughout the\n\t\t\tentire lifetime of the device, which could be\n\t\t\tyears or decades. Some external protective\n\t\t\tmeasures and mitigations might be employed to\n\t\t\taid in preventing or reducing the risk of\n\t\t\tmalicious attack, but the root weakness cannot\n...", "consequences": [{"scope": ["Confidentiality", "Integrity", "Access Control", "Authentication", "Authorization"], "impact": ["Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Execute Unauthorized Code or Commands", "DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Specify requirements to include the ability to update the firmware. Include integrity checks and authentication to ensure that untrusted firmware cannot be installed.", "phase": ["Requirements"]}, {"description": "Design the device to allow for updating the firmware. Ensure that the design specifies how to distribute the updates and ensure their integrity and authentication.", "phase": ["Architecture and Design"]}, {"description": "Implement the necessary functionality to allow the firmware to be updated.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Manual Analysis", "description": "Create a new installable boot image of the current build with a minor version number change. Use the standard installation method to update the boot image. Verify that the minor version number has cha..."}, {"method": "Architecture or Design Review", "description": "Check the consumer or maintainer documentation, the architecture/design documentation, or the original requirements to ensure that the documentation includes details for how to update the firmware."}, {"method": "Manual Dynamic Analysis", "description": "Determine if there is a lack of a capability to update read-only memory (ROM) structure. This could manifest as a difference between the latest firmware version and the current version within the devi..."}], "observed_examples": [{"cve": "CVE-2020-9054", "description": "Chain: network-attached storage (NAS) device has a critical OS command injection (CWE-78) vulnerability that is actively exploited to place IoT device..."}, {"cve": "[REF-1095]", "description": "A hardware \"smart lock\" has weak key generation that allows attackers to steal the key by BLE sniffing, but the device's firmware cannot be upgraded a..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1278": {"name": "Missing Protection Against Hardware Reverse Engineering Using Integrated Circuit (IC) Imaging Techniques", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Information stored in hardware may be recovered by an attacker with the capability to capture and analyze images of the integrated circuit using techniques such as scanning electron microscopy.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "The cost of secret extraction via IC reverse engineering should outweigh the potential value of the secrets being extracted. Threat model and value of secrets should be used to choose the technology used to safeguard those secrets. Examples include IC camouflaging and obfuscation, tamper-proof packa...", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1279": {"name": "Cryptographic Operations are run Before Supporting Units are Ready", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Performing cryptographic operations without ensuring that the supporting inputs are ready to supply valid data may compromise the cryptographic result.", "extended_description": "Many cryptographic hardware units depend upon other hardware units to supply information to them to produce a securely encrypted result. For example, a cryptographic unit that depends on an external random-number-generator (RNG) unit for entropy must wait until the RNG unit is producing random numbers. If a cryptographic unit retrieves a private encryption key from a fuse unit, the fuse unit must be up and running before a key may be supplied.", "consequences": [{"scope": ["Access Control", "Confidentiality", "Integrity", "Availability", "Accountability", "Authentication", "Authorization", "Non-Repudiation"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Best practices should be used to design cryptographic systems.", "phase": ["Architecture and Design"]}, {"description": "Continuously ensuring that cryptographic inputs are supplying valid information is necessary to ensure that the encrypted output is secure.", "phase": ["Implementation"]}], "platforms": {"languages": ["Verilog", "VHDL", "Not Language-Specific"], "technologies": ["Processor Hardware", "Not Technology-Specific"]}}, "128": {"name": "Wrap-around Error", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Wrap around errors occur whenever a value is incremented past the maximum value for its type and therefore \"wraps around\" to a very small, negative, or undefined value.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Instability"]}, {"scope": ["Integrity"], "impact": ["Modify Memory"]}, {"scope": ["Confidentiality", "Availability", "Access Control"], "impact": ["Execute Unauthorized Code or Commands", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Requirements specification: The choice could be made to use a language that is not susceptible to these issues."}, {"description": "Provide clear upper and lower bounds on the scale of any protocols designed.", "phase": ["Architecture and Design"]}, {"description": "Perform validation on all incremented variables to ensure that they remain within reasonable bounds.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C", "C++"]}}, "1280": {"name": "Access Control Check Implemented After Asset is Accessed", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A product's hardware-based access control check occurs after the asset has been accessed.", "consequences": [{"scope": ["Access Control", "Confidentiality", "Integrity"], "impact": ["Modify Memory", "Read Memory", "Modify Application Data", "Read Application Data", "Gain Privileges or Assume Identity", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Implement the access control check first. Access should only be given to asset if agent is authorized.", "phase": ["Implementation"]}], "platforms": {"languages": ["Verilog", "VHDL", "Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1281": {"name": "Sequence of Processor Instructions Leads to Unexpected Behavior", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Specific combinations of processor instructions lead to undesirable behavior such as locking the processor until a hard reset performed.", "consequences": [{"scope": ["Integrity", "Availability"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Implement a rigorous testing strategy that incorporates randomization to explore instruction sequences that are unlikely to appear in normal workloads in order to identify halt and catch fire instruction sequences.", "phase": ["Testing"]}, {"description": "Patch operating system to avoid running Halt and Catch Fire type sequences or to mitigate the damage caused by unexpected behavior.  See [REF-1108].", "phase": ["Patching and Maintenance"]}], "observed_examples": [{"cve": "CVE-2021-26339", "description": "A bug in AMD CPU's core logic allows a potential DoS by using a specific x86 instruction sequence to hang the processor"}, {"cve": "CVE-1999-1476", "description": "A bug in some Intel Pentium processors allow DoS (hang) via an invalid \"CMPXCHG8B\" instruction, causing a deadlock"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Processor Hardware"]}}, "1282": {"name": "Assumed-Immutable Data is Stored in Writable Memory", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Immutable data, such as a first-stage bootloader, device identifiers, and \"write-once\" configuration settings are stored in writable memory that can be re-programmed or updated in the field.", "consequences": [{"scope": ["Integrity"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "All immutable code or data should be programmed into ROM or write-once memory.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1283": {"name": "Mutable Attestation or Measurement Reporting Data", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The register contents used for attestation or measurement reporting data to verify boot flow are modifiable by an adversary.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory", "Read Application Data"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1284": {"name": "Improper Validation of Specified Quantity in Input", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.", "consequences": [{"scope": ["Other", "Integrity", "Availability"], "impact": ["Varies by Context", "DoS: Resource Consumption (CPU)", "Modify Memory", "Read Memory"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2025-46687", "description": "Chain: Javascript engine code does not perform a length check (CWE-1284) leading to integer overflow (CWE-190) causing allocation of smaller buffer th..."}, {"cve": "CVE-2019-19911", "description": "Chain: Python library does not limit the resources used to process images that specify a very large number of bands (CWE-1284), leading to excessive m..."}, {"cve": "CVE-2008-1440", "description": "lack of validation of length field leads to infinite loop"}, {"cve": "CVE-2008-2374", "description": "lack of validation of string length fields allows memory consumption or buffer over-read"}], "platforms": {"languages": ["Not Language-Specific"]}}, "1285": {"name": "Improper Validation of Specified Index, Position, or Offset in Input", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input that is expected to specify an index, position, or offset into an indexable resource such as a buffer or file, but it does not validate or incorrectly validates that the specified index/position/offset has the required properties.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2005-0369", "description": "large ID in packet used as array index"}, {"cve": "CVE-2001-1009", "description": "negative array index as argument to POP LIST command"}], "platforms": {"languages": ["Not Language-Specific"]}}, "1286": {"name": "Improper Validation of Syntactic Correctness of Input", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "observed_examples": [{"cve": "CVE-2016-4029", "description": "Chain: incorrect validation of intended decimal-based IP address format (CWE-1286) enables parsing of octal or hexadecimal formats (CWE-1389), allowin..."}, {"cve": "CVE-2007-5893", "description": "HTTP request with missing protocol version number leads to crash"}], "platforms": {"languages": ["Not Language-Specific"]}}, "1287": {"name": "Improper Validation of Specified Type of Input", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "observed_examples": [{"cve": "CVE-2024-37032", "description": "Large language model (LLM) management tool does not\n               validate the format of a digest value (CWE-1287) from a\n               private, unt..."}, {"cve": "CVE-2008-2223", "description": "SQL injection through an ID that was supposed to be numeric."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1288": {"name": "Improper Validation of Consistency within Input", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives a complex input with multiple elements or fields that must be consistent with each other, but it does not validate or incorrectly validates that the input is actually consistent.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "observed_examples": [{"cve": "CVE-2018-16733", "description": "product does not validate that the start block appears before the end block"}, {"cve": "CVE-2006-3790", "description": "size field that is inconsistent with packet size leads to buffer over-read"}, {"cve": "CVE-2008-4114", "description": "system crash with offset value that is inconsistent with packet size"}], "platforms": {"languages": ["Not Language-Specific"]}}, "1289": {"name": "Improper Validation of Unsafe Equivalence in Input", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "observed_examples": [{"cve": "CVE-2021-39155", "description": "Chain: A microservice integration and management platform compares the hostname in the HTTP Host header in a case-sensitive way (CWE-178, CWE-1289), a..."}, {"cve": "CVE-2020-11053", "description": "Chain: Go-based Oauth2 reverse proxy can send the authenticated user to another site at the end of the authentication flow. A redirect URL with HTML-e..."}, {"cve": "CVE-2005-0269", "description": "File extension check in forum software only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary ..."}, {"cve": "CVE-2001-1238", "description": "Task Manager does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.e..."}, {"cve": "CVE-2004-2214", "description": "HTTP server allows bypass of access restrictions using URIs with mixed case."}], "platforms": {"languages": ["Not Language-Specific"]}}, "129": {"name": "Improper Validation of Array Index", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Integrity"], "impact": ["Modify Memory"]}, {"scope": ["Confidentiality", "Integrity"], "impact": ["Modify Memory", "Read Memory"]}, {"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Integrity", "Availability", "Confidentiality"], "impact": ["DoS: Crash, Exit, or Restart", "Execute Unauthorized Code or Commands", "Read Memory", "Modify Memory"]}], "mitigations": [{"description": "Use an input validation framework such as Struts or the OWASP ESAPI Validation API. Note that using a framework does not automatically address all input validation problems; be mindful of weaknesses that could arise from misusing the framework itself (CWE-1173).", "phase": ["Architecture and Design"]}, {"description": "Be especially careful to validate all input when invoking code that crosses language boundaries, such as from an interpreted language to native code. This could create an unexpected interaction between the language boundaries. Ensure that you are not violating any of the expectations of the language...", "phase": ["Implementation"]}, {"description": "Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the s...", "phase": ["Architecture and Design", "Operation"]}], "detection_methods": [{"method": "Automated Static Analysis"}, {"method": "Automated Dynamic Analysis", "description": "This weakness can be detected using dynamic tools and techniques that interact with the software using large test suites with many diverse inputs, such as fuzz testing (fuzzing), robustness testing, a..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t      compilation to insert runtime error-checking mechanisms\n\t      related to memory safety errors, such as AddressSanitizer\n\t      (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2005-0369", "description": "large ID in packet used as array index"}, {"cve": "CVE-2001-1009", "description": "negative array index as argument to POP LIST command"}, {"cve": "CVE-2003-0721", "description": "Integer signedness error leads to negative array index"}, {"cve": "CVE-2004-1189", "description": "product does not properly track a count and a maximum number, which can lead to resultant array index overflow."}, {"cve": "CVE-2007-5756", "description": "Chain: device driver for packet-capturing software allows access to an unintended IOCTL with resultant array index error."}], "platforms": {"languages": ["C", "C++", "Not Language-Specific"]}}, "1290": {"name": "Incorrect Decoding of Security Identifiers ", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product implements a decoding mechanism to decode certain bus-transaction signals to security identifiers. If the decoding is implemented incorrectly, then untrusted agents can now gain unauthorized access to the asset.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Modify Memory", "Read Memory", "DoS: Resource Consumption (Other)", "Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity", "Quality Degradation"]}], "mitigations": [{"description": "Security identifier decoders must be reviewed for design consistency and common weaknesses.", "phase": ["Architecture and Design"]}, {"description": "Access and programming flows must be tested in pre-silicon and post-silicon testing in order to check for this weakness.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Bus/Interface Hardware", "Not Technology-Specific"]}}, "1291": {"name": "Public Key Re-Use for Signing both Debug and Production Code", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The same public key is used for signing both debug and production code.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control", "Accountability", "Authentication", "Authorization", "Non-Repudiation", "Other"], "impact": ["Read Memory", "Modify Memory", "Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity", "Varies by Context"]}], "mitigations": [{"description": "Use different keys for Production and Debug.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Architecture or Design Review"}, {"method": "Dynamic Analysis with Manual Results Interpretation"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1292": {"name": "Incorrect Conversion of Security Identifiers", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product implements a conversion mechanism to map certain bus-transaction signals to security identifiers. However, if the conversion is incorrectly implemented, untrusted agents can gain unauthorized access to the asset.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Modify Memory", "Read Memory", "DoS: Resource Consumption (Other)", "Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity", "Quality Degradation"]}], "mitigations": [{"description": "Security identifier decoders must be reviewed for design inconsistency and common weaknesses.", "phase": ["Architecture and Design"]}, {"description": "Access and programming flows must be tested in pre-silicon and post-silicon testing.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Bus/Interface Hardware", "Not Technology-Specific"]}}, "1293": {"name": "Missing Source Correlation of Multiple Independent Data", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product relies on one source of data, preventing the ability to detect if an adversary has compromised a data source.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Design system to use a Practical Byzantine fault method, to request information from multiple sources to verify the data and report on potentially compromised information sources.", "phase": ["Requirements"]}, {"description": "Failure to use a Practical Byzantine fault method when requesting data. Lack of place to report potentially compromised information sources. Relying on non-independent information sources for integrity checking. Failure to report information sources that respond in the minority to incident response ...", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1294": {"name": "Insecure Security Identifier Mechanism", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The System-on-Chip (SoC) implements a Security Identifier mechanism to differentiate what actions are allowed or disallowed when a transaction originates from an entity. However, the Security Identifiers are not correctly implemented.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Modify Memory", "Read Memory", "DoS: Resource Consumption (Other)", "Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity", "Quality Degradation"]}], "mitigations": [{"description": "Security Identifier Decoders must be reviewed for design inconsistency and common weaknesses.", "phase": ["Architecture and Design"]}, {"description": "Access and programming flows must be tested in pre-silicon and post-silicon testing.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Bus/Interface Hardware", "Not Technology-Specific"]}}, "1295": {"name": "Debug Messages Revealing Unnecessary Information", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product fails to adequately prevent the revealing of unnecessary and potentially sensitive system information within debugging messages.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control", "Accountability", "Authentication", "Authorization", "Non-Repudiation"], "impact": ["Read Memory", "Bypass Protection Mechanism", "Gain Privileges or Assume Identity", "Varies by Context"]}], "mitigations": [{"description": "Ensure that a debug message does not reveal any unnecessary information during the debug process for the intended response.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2021-25476", "description": "Digital Rights Management (DRM) capability for mobile platform leaks pointer information, simplifying ASLR bypass"}, {"cve": "CVE-2020-24491", "description": "Processor generates debug message that contains sensitive information (\"addresses of memory transactions\")."}, {"cve": "CVE-2017-18326", "description": "modem debug messages include cryptographic keys"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1296": {"name": "Incorrect Chaining or Granularity of Debug Components", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product's debug components contain incorrect chaining or granularity of debug components.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Access Control", "Authentication", "Authorization", "Availability", "Accountability"], "impact": ["Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Execute Unauthorized Code or Commands", "Modify Memory", "Modify Files or Directories"]}], "mitigations": [{"description": "Ensure that debug components are properly chained and their granularity is maintained at different authentication levels.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Architecture or Design Review", "description": "Appropriate Post-Si tests should be carried out at various authorization levels to ensure that debug components are properly chained and accessible only to users with appropriate credentials."}, {"method": "Dynamic Analysis with Manual Results Interpretation", "description": "Appropriate Post-Si tests should be carried out at various authorization levels to ensure that debug components are properly chained and accessible only to users with appropriate credentials."}], "observed_examples": [{"cve": "CVE-2017-18347", "description": "Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers to extract the device's prote..."}, {"cve": "CVE-2020-1791", "description": "There is an improper authorization vulnerability in several smartphones.  The system has a logic-judging error, and, under certain scenarios, a succes..."}], "platforms": {"languages": ["Verilog", "VHDL", "Not Language-Specific"], "technologies": ["Processor Hardware", "Not Technology-Specific"]}}, "1297": {"name": "Unprotected Confidential Information on Device is Accessible by OSAT Vendors", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not adequately protect confidential information on the device from being accessed by Outsourced Semiconductor Assembly and Test (OSAT) vendors.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Access Control", "Authentication", "Authorization", "Availability", "Accountability", "Non-Repudiation"], "impact": ["Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Execute Unauthorized Code or Commands", "Modify Memory", "Modify Files or Directories"]}], "detection_methods": [{"method": "Architecture or Design Review", "description": "Appropriate Post-Si tests should be carried out to ensure that residual confidential information is not left on parts leaving one facility for another facility."}, {"method": "Dynamic Analysis with Manual Results Interpretation", "description": "Appropriate Post-Si tests should be carried out to ensure that residual confidential information is not left on parts leaving one facility for another facility."}], "platforms": {"languages": ["Verilog", "VHDL", "Not Language-Specific"], "technologies": ["Processor Hardware", "Not Technology-Specific"]}}, "1298": {"name": "Hardware Logic Contains Race Conditions", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A race condition in the hardware logic results in undermining security guarantees of the system.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity", "Alter Execution Logic"]}], "mitigations": [{"description": "Adopting design practices that encourage designers to recognize and eliminate race conditions, such as Karnaugh maps, could result in the decrease in occurrences of race conditions.", "phase": ["Architecture and Design"]}, {"description": "Logic redundancy can be implemented along security critical paths to prevent race conditions. To avoid metastability, it is a good practice in general to default to a secure state in which access is not given to untrusted agents.", "phase": ["Implementation"]}], "platforms": {"languages": ["Verilog", "VHDL"], "technologies": ["System on Chip"]}}, "1299": {"name": "Missing Protection Mechanism for Alternate Hardware Interface", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The lack of protections on alternate paths to access\n                control-protected assets (such as unprotected shadow registers\n                and other external facing unguarded interfaces) allows an\n                attacker to bypass existing protections to the asset that are\n\t\tonly performed against the primary path.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Modify Memory", "Read Memory", "DoS: Resource Consumption (Other)", "Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity", "Alter Execution Logic", "Bypass Protection Mechanism", "Quality Degradation"]}], "mitigations": [{"description": "Protect assets from accesses against all potential interfaces and alternate paths.", "phase": ["Requirements"]}, {"description": "Protect assets from accesses against all potential interfaces and alternate paths.", "phase": ["Architecture and Design"]}, {"description": "Protect assets from accesses against all potential interfaces and alternate paths.", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2022-38399", "description": "Missing protection mechanism on serial connection allows for arbitrary OS command execution."}, {"cve": "CVE-2020-9285", "description": "Mini-PCI Express slot does not restrict direct memory access."}, {"cve": "CVE-2020-8004", "description": "When the internal flash is protected by blocking access on the Data Bus (DBUS), it can still be indirectly accessed through the Instruction Bus (IBUS)..."}, {"cve": "CVE-2017-18293", "description": "When GPIO is protected by blocking access\n                        to corresponding GPIO resource registers,\n                        protection can be ..."}, {"cve": "CVE-2020-15483", "description": "monitor device allows access to physical UART debug port without authentication"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Microcontroller Hardware", "Processor Hardware", "Bus/Interface Hardware", "Not Technology-Specific"]}}, "13": {"name": "ASP.NET Misconfiguration: Password in Configuration File", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Storing a plaintext password in a configuration file allows anyone who can read the file access to the password-protected resource making them an easy target for attackers.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Credentials stored in configuration files should be encrypted, Use standard APIs and industry accepted algorithms to encrypt the credentials stored in configuration files.", "phase": ["Implementation"]}], "platforms": {"languages": ["ASP.NET"]}}, "130": {"name": "Improper Handling of Length Parameter Inconsistency", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.", "extended_description": "If an attacker can manipulate the length parameter associated with an input such that it is inconsistent with the actual length of the input, this can be leveraged to cause the target application to behave in unexpected, and possibly, malicious ways. One of the possible motives for doing so is to pass in arbitrarily large input to the application. Another possible motivation is the modification of application state by including invalid data for subsequent properties of the application. Such weak...", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Memory", "Modify Memory", "Varies by Context"]}], "mitigations": [{"description": "When processing structured incoming data containing a size field followed by raw data, ensure that you identify and resolve any inconsistencies between the size field and the actual size of the data.", "phase": ["Implementation"]}, {"description": "Do not let the user control the size of the buffer.", "phase": ["Implementation"]}, {"description": "Validate that the length of the user-supplied data is consistent with the buffer size.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2014-0160", "description": "Chain: \"Heartbleed\" bug receives an inconsistent length parameter (CWE-130) enabling an out-of-bounds read (CWE-126), returning memory that could incl..."}, {"cve": "CVE-2009-2299", "description": "Web application firewall consumes excessive memory when an HTTP request contains a large Content-Length value but no POST data."}, {"cve": "CVE-2001-0825", "description": "Buffer overflow in internal string handling routine allows remote attackers to execute arbitrary commands via a length argument of zero or less, which..."}, {"cve": "CVE-2001-1186", "description": "Web server allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the re..."}, {"cve": "CVE-2001-0191", "description": "Service does not properly check the specified length of a cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, o..."}], "platforms": {"languages": ["C", "C++", "Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1300": {"name": "Improper Protection of Physical Side Channels", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The device does not contain sufficient protection\n\tmechanisms to prevent physical side channels from exposing\n\tsensitive information due to patterns in physically observable\n\tphenomena such as variations in power consumption,\n\telectromagnetic emissions (EME), or acoustic emissions.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory", "Read Application Data"]}], "mitigations": [{"description": "Apply blinding or masking techniques to implementations of cryptographic algorithms.", "phase": ["Architecture and Design"]}, {"description": "Add shielding or tamper-resistant protections to the device to increase the difficulty of obtaining measurements of the side-channel.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Manual Analysis", "description": "Perform a set of leakage detection tests such as the procedure outlined in the Test Vector Leakage Assessment (TVLA) test requirements for AES [REF-1230].  TVLA is the basis for the ISO standard 17825..."}, {"method": "Manual Analysis"}, {"method": "Manual Analysis"}], "observed_examples": [{"cve": "CVE-2022-35888", "description": "Power side-channels leak secret information from processor"}, {"cve": "CVE-2021-3011", "description": "electromagnetic-wave side-channel in security-related microcontrollers allows extraction of private key"}, {"cve": "CVE-2019-14353", "description": "Crypto hardware wallet's power consumption relates to total number of pixels illuminated, creating a side channel in the USB connection that allows at..."}, {"cve": "CVE-2020-27211", "description": "Chain: microcontroller system-on-chip contains uses a register value stored in flash to set product protection state on the memory bus but does not co..."}, {"cve": "CVE-2013-4576", "description": "message encryption software uses certain instruction sequences that allows RSA key extraction using a chosen-ciphertext attack and acoustic cryptanaly..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1301": {"name": "Insufficient or Incomplete Data Removal within Hardware Component", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product's data removal process does not completely delete all data and potentially sensitive information within hardware components.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory", "Read Application Data"]}], "mitigations": [{"description": "Apply blinding or masking techniques to implementations of cryptographic algorithms.", "phase": ["Architecture and Design"]}, {"description": "Alter the method of erasure, add protection of media, or destroy the media to protect the data.", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2019-8575", "description": "Firmware Data Deletion Vulnerability in which a base station factory reset might not delete all user information. The impact of this enables a new own..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1302": {"name": "Missing Source Identifier in Entity Transactions on a System-On-Chip (SOC)", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product implements a security identifier mechanism to differentiate what actions are allowed or disallowed when a transaction originates from an entity. A transaction is sent without a security identifier.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Modify Memory", "Read Memory", "DoS: Crash, Exit, or Restart", "Bypass Protection Mechanism", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Transaction details must be reviewed for design inconsistency and common weaknesses.", "phase": ["Architecture and Design"]}, {"description": "Security identifier definition and programming flow must be tested in pre-silicon and post-silicon testing.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1303": {"name": "Non-Transparent Sharing of Microarchitectural Resources", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Hardware structures shared across execution contexts (e.g., caches and branch predictors) can violate the expected architecture isolation between contexts.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data", "Read Memory"]}], "mitigations": [{"description": "Microarchitectural covert channels can be addressed using a mixture of hardware and software mitigation techniques. These include partitioned caches, new barrier and flush instructions, and disabling high resolution performance counters and timers.", "phase": ["Architecture and Design"]}, {"description": "Microarchitectural covert channels can be addressed using a mixture of hardware and software mitigation techniques. These include partitioned caches, new barrier and flush instructions, and disabling high resolution performance counters and timers.", "phase": ["Requirements"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1304": {"name": "Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product performs a power save/restore\n            operation, but it does not ensure that the integrity of\n            the configuration state is maintained and/or verified between\n\t    the beginning and ending of the operation.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["DoS: Instability", "DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (Other)", "Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Alter Execution Logic", "Quality Degradation", "Unexpected State", "Reduce Maintainability", "Reduce Performance", "Reduce Reliability"]}], "mitigations": [{"description": "Inside the IP, incorporate integrity checking\n                        on the configuration state via a cryptographic\n                        hash. The hash can be protected inside the IP such as\n                        by storing it in internal registers which never lose\n                        powe...", "phase": ["Architecture and Design"]}, {"description": "Outside the IP, incorporate integrity checking\n                        of the configuration state via a trusted agent. Before\n                        powering down, the trusted agent performs a hash of the\n                        configuration and saves the hash in persistent storage.\n              ...", "phase": ["Integration"]}, {"description": "Outside the IP, incorporate a protected\n                        environment that prevents undetected modification of\n                        the configuration state by untrusted agents. Before\n                        powering down, a trusted agent saves the IP's\n                        configuration...", "phase": ["Integration"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "131": {"name": "Incorrect Calculation of Buffer Size", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Availability", "Confidentiality"], "impact": ["DoS: Crash, Exit, or Restart", "Execute Unauthorized Code or Commands", "Read Memory", "Modify Memory"]}], "mitigations": [{"description": "When allocating a buffer for the purpose of transforming, converting, or encoding an input, allocate enough memory to handle the largest possible encoding. For example, in a routine that converts \"&\" characters to \"&amp;\" for HTML entity encoding, the output buffer needs to be at least 5 times as la...", "phase": ["Implementation"]}, {"description": "Perform input validation on any numeric input by ensuring that it is within the expected range. Enforce that the input meets both the minimum and maximum requirements for the expected range.", "phase": ["Implementation"]}, {"description": "For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-s...", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis"}, {"method": "Automated Dynamic Analysis", "description": "This weakness can be detected using dynamic tools and techniques that interact with the software using large test suites with many diverse inputs, such as fuzz testing (fuzzing), robustness testing, a..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2025-46687", "description": "Chain: Javascript engine code does not perform a length check (CWE-1284) leading to integer overflow (CWE-190) causing allocation of smaller buffer th..."}, {"cve": "CVE-2025-27363", "description": "Font rendering library does not properly\n               handle assigning a signed short value to an unsigned\n               long (CWE-195), leading to..."}, {"cve": "CVE-2020-17087", "description": "Chain: integer truncation (CWE-197) causes small buffer allocation (CWE-131) leading to out-of-bounds write (CWE-787) in kernel pool, as exploited in ..."}, {"cve": "CVE-2004-1363", "description": "substitution overflow: buffer overflow using environment variables that are expanded after the length check is performed"}, {"cve": "CVE-2004-0747", "description": "substitution overflow: buffer overflow using expansion of environment variables"}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "1310": {"name": "Missing Ability to Patch ROM Code", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Missing an ability to patch ROM code may leave a System or System-on-Chip (SoC) in a vulnerable state.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context", "Reduce Maintainability"]}], "mitigations": [{"description": "Secure patch support to allow ROM code to be patched on the next boot.", "phase": ["Architecture and Design", "Implementation"]}, {"description": "Support patches that can be programmed in-field or during manufacturing through hardware fuses. This feature can be used for limited patching of devices after shipping, or for the next batch of silicon devices manufactured, without changing the full device ROM.", "phase": ["Architecture and Design", "Implementation"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip"]}}, "1311": {"name": "Improper Translation of Security Attributes by Fabric Bridge", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The bridge incorrectly translates security attributes from either trusted to untrusted or from untrusted to trusted when converting from one fabric protocol to another.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Access Control"], "impact": ["Modify Memory", "Read Memory", "Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "The translation must map signals in such a way that untrusted agents cannot map to trusted agents or vice-versa.", "phase": ["Architecture and Design"]}, {"description": "Ensure that the translation maps signals in such a way that untrusted agents cannot map to trusted agents or vice-versa.", "phase": ["Implementation"]}], "platforms": {"languages": ["Verilog", "VHDL"], "technologies": ["Not Technology-Specific"]}}, "1312": {"name": "Missing Protection for Mirrored Regions in On-Chip Fabric Firewall", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The firewall in an on-chip fabric protects the main addressed region, but it does not protect any mirrored memory or memory-mapped-IO (MMIO) regions.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Access Control"], "impact": ["Modify Memory", "Read Memory", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "The fabric firewall should apply the same protections as the original region to the mirrored regions.", "phase": ["Architecture and Design"]}, {"description": "The fabric firewall should apply the same protections as the original region to the mirrored regions.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Manual Dynamic Analysis", "description": "Using an external debugger, send write transactions to mirrored regions to test if original, write-protected regions are modified. Similarly, send read transactions to mirrored regions to test if the ..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1313": {"name": "Hardware Allows Activation of Test or Debug Logic at Runtime", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "During runtime, the hardware allows for test or debug logic (feature) to be activated, which allows for changing the state of the hardware. This feature can alter the intended behavior of the system and allow for alteration and leakage of sensitive data by an adversary.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Modify Memory", "Read Memory", "DoS: Crash, Exit, or Restart", "DoS: Instability", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Resource Consumption (Other)", "Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Alter Execution Logic", "Quality Degradation", "Unexpected State", "Reduce Performance", "Reduce Reliability"]}], "mitigations": [{"description": "Insert restrictions on when the hardware's test or debug features can be activated. For example, during normal operating modes, the hardware's privileged modes that allow access to such features cannot be activated. Configuring the hardware to only enter a test or debug mode within a window of oppor...", "phase": ["Architecture and Design"]}, {"description": "Insert restrictions on when the hardware's test or debug features can be activated. For example, during normal operating modes, the hardware's privileged modes that allow access to such features cannot be activated. Configuring the hardware to only enter a test or debug mode within a window of oppor...", "phase": ["Implementation"]}, {"description": "Insert restrictions on when the hardware's test or debug features can be activated. For example, during normal operating modes, the hardware's privileged modes that allow access to such features cannot be activated. Configuring the hardware to only enter a test or debug mode within a window of oppor...", "phase": ["Integration"]}], "observed_examples": [{"cve": "CVE-2021-33150", "description": "Hardware processor allows activation of test or debug logic at runtime."}, {"cve": "CVE-2021-0146", "description": "Processor allows the activation of test or debug logic at runtime, allowing escalation of privileges"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1314": {"name": "Missing Write Protection for Parametric Data Values", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The device does not write-protect the parametric data values for sensors that scale the sensor value, allowing untrusted software to manipulate the apparent result and potentially damage hardware or cause operational failure.", "consequences": [{"scope": ["Availability"], "impact": ["Quality Degradation", "DoS: Resource Consumption (Other)"]}], "mitigations": [{"description": "Access controls for sensor blocks should ensure that only trusted software is allowed to change threshold limits and sensor parametric data.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2017-8252", "description": "Kernel can inject faults in computations during the execution of TrustZone leading to information disclosure in Snapdragon Auto, Snapdragon Compute, S..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Sensor Hardware"]}}, "1315": {"name": "Improper Setting of Bus Controlling Capability in Fabric End-point", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The bus controller enables bits in the fabric end-point to allow responder devices to control transactions on the fabric.", "consequences": [{"scope": ["Access Control"], "impact": ["Modify Memory", "Read Memory", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "For responder devices, the register bit in the fabric end-point that enables the bus controlling capability must be set to 0 by default. This bit should not be set during secure-boot flows. Also, writes to this register must be access-protected to prevent malicious modifications to obtain bus-contro...", "phase": ["Architecture and Design"]}, {"description": "For responder devices, the register bit in the fabric end-point that enables the bus controlling capability must be set to 0 by default. This bit should not be set during secure-boot flows. Also, writes to this register must be access-protected to prevent malicious modifications to obtain bus-contro...", "phase": ["Implementation"]}, {"description": "For responder devices, the register bit in the fabric end-point that enables the bus controlling capability must be set to 0 by default. This bit should not be set during secure-boot flows. Also, writes to this register must be access-protected to prevent malicious modifications to obtain bus-contro...", "phase": ["System Configuration"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1316": {"name": "Fabric-Address Map Allows Programming of Unwarranted Overlaps of Protected and Unprotected Ranges", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The address map of the on-chip fabric has protected and unprotected regions overlapping, allowing an attacker to bypass access control to the overlapping portion of the protected region.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Access Control", "Authorization"], "impact": ["Bypass Protection Mechanism", "Read Memory", "Modify Memory"]}], "mitigations": [{"description": "When architecting the address map of the chip, ensure that protected and unprotected ranges are isolated and do not overlap. When designing, ensure that ranges hardcoded in Register-Transfer Level (RTL) do not overlap.", "phase": ["Architecture and Design"]}, {"description": "Ranges configured by firmware should not overlap. If overlaps are mandatory because of constraints such as a limited number of registers, then ensure that no assets are present in the overlapped portion.", "phase": ["Implementation"]}, {"description": "Validate mitigation actions with robust testing.", "phase": ["Testing"]}], "detection_methods": [{"method": "Automated Dynamic Analysis", "description": "Review address map in specification to see if there are any overlapping ranges."}, {"method": "Manual Static Analysis", "description": "Negative testing of access control on overlapped ranges."}], "observed_examples": [{"cve": "CVE-2009-4419", "description": "Attacker can modify MCHBAR register to overlap with an attacker-controlled region, which modification prevents the SENTER instruction from properly ap..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Bus/Interface Hardware", "Not Technology-Specific"]}}, "1317": {"name": "Improper Access Control in Fabric Bridge", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a fabric bridge for transactions between two Intellectual Property (IP) blocks, but the bridge does not properly perform the expected privilege, identity, or other access control checks between those IP blocks.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Access Control", "Availability"], "impact": ["DoS: Crash, Exit, or Restart", "Bypass Protection Mechanism", "Read Memory", "Modify Memory"]}], "mitigations": [{"description": "Ensure that the design includes provisions for access-control checks in the bridge for both upstream and downstream transactions.", "phase": ["Architecture and Design"]}, {"description": "Implement access-control checks in the bridge for both upstream and downstream transactions.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Simulation / Emulation", "description": "RTL simulation to ensure that bridge-access controls are implemented properly."}, {"method": "Formal Verification", "description": "Formal verification of bridge RTL to ensure that access control cannot be bypassed."}], "observed_examples": [{"cve": "CVE-2019-6260", "description": "Baseboard Management Controller (BMC) device implements Advanced High-performance Bus (AHB) bridges that do not require authentication for arbitrary r..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Processor Hardware", "Not Technology-Specific"]}}, "1318": {"name": "Missing Support for Security Features in On-chip Fabrics or Buses", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "On-chip fabrics or buses either do not support or are not configured to support privilege separation or other security features, such as access control.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Access Control", "Availability"], "impact": ["DoS: Crash, Exit, or Restart", "Read Memory", "Modify Memory"]}], "mitigations": [{"description": "If fabric does not support security features, implement security checks in a bridge or any component that is between the master and the fabric.  Alternatively, connect all fabric slaves that do not have any security assets under one such fabric and connect peripherals with security assets to a diffe...", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Architecture or Design Review", "description": "Review the fabric specification and ensure that it contains signals to transfer security-sensitive signals."}, {"method": "Manual Static Analysis - Source Code", "description": "Lack of security features can also be confirmed through manual RTL review of the fabric RTL."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Processor Hardware", "Not Technology-Specific"]}}, "1319": {"name": "Improper Protection against Electromagnetic Fault Injection (EM-FI)", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The device is susceptible to electromagnetic fault injection attacks, causing device internal information to be compromised or security mechanisms to be bypassed.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Access Control", "Availability"], "impact": ["Modify Memory", "Read Memory", "Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Execute Unauthorized Code or Commands"]}], "observed_examples": [{"cve": "CVE-2020-27211", "description": "Chain: microcontroller system-on-chip uses a register value stored in flash to set product protection state on the memory bus and does not contain pro..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip", "Microcontroller Hardware", "Memory Hardware", "Power Management Hardware", "Processor Hardware", "Test/Debug Hardware", "Sensor Hardware"]}}, "132": {"name": "DEPRECATED: Miscalculated Null Termination", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "This entry has been deprecated because it was a duplicate of CWE-170. All content has been transferred to CWE-170."}, "1320": {"name": "Improper Protection for Outbound Error Messages and Alert Signals", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Untrusted agents can disable alerts about signal conditions exceeding limits or the response mechanism that handles such alerts.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Instability", "DoS: Crash, Exit, or Restart", "Reduce Reliability", "Unexpected State"]}], "mitigations": [{"description": "Alert signals generated by critical events should be protected from access by untrusted agents. Only hardware or trusted firmware modules should be able to alter the alert configuration.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip", "Microcontroller Hardware", "Memory Hardware", "Power Management Hardware", "Processor Hardware", "Test/Debug Hardware", "Sensor Hardware"]}}, "1321": {"name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Read Application Data", "Modify Application Data"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "By freezing the object prototype first (for example, Object.freeze(Object.prototype)), modification of the prototype becomes impossible.", "phase": ["Implementation"]}, {"description": "By blocking modifications of attributes that resolve to object prototype, such as proto or prototype, this weakness can be mitigated.", "phase": ["Architecture and Design"]}, {"description": "When handling untrusted objects, validating using a schema can be used.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2018-3721", "description": "Prototype pollution by merging objects."}, {"cve": "CVE-2019-10744", "description": "Prototype pollution by setting default values to object attributes recursively."}, {"cve": "CVE-2019-11358", "description": "Prototype pollution by merging objects recursively."}, {"cve": "CVE-2020-8203", "description": "Prototype pollution by setting object attributes based on dot-separated path."}], "platforms": {"languages": ["JavaScript"]}}, "1322": {"name": "Use of Blocking Code in Single-threaded, Non-blocking Context", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a non-blocking model that relies on a single threaded process\n\t\t\tfor features such as scalability, but it contains code that can block when it is invoked.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)"]}], "mitigations": [{"description": "Generally speaking, blocking calls should be\n\t\t\t\t\treplaced with non-blocking alternatives that can be used asynchronously.\n\t\t\t\t\tExpensive computations should be passed off to worker threads, although\n\t\t\t\t\tthe correct approach depends on the framework being used.", "phase": ["Implementation"]}, {"description": "For expensive computations, consider breaking them up into\n\t\t\t\t\tmultiple smaller computations. Refer to the documentation of the\n\t\t\t\t\tframework being used for guidance.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "1323": {"name": "Improper Management of Sensitive Trace Data", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Trace data collected from several sources on the\n                System-on-Chip (SoC) is stored in unprotected locations or\n                transported to untrusted agents.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}], "mitigations": [{"description": "Tag traces to indicate owner and debugging privilege level (designer, OEM, or end user) needed to access that trace.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip"]}}, "1324": {"name": "DEPRECATED: Sensitive Information Accessible by Physical Probing of JTAG Interface", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "This entry has been deprecated because it was at a lower level of abstraction than supported by CWE. All relevant content has been integrated into CWE-319."}, "1325": {"name": "Improperly Controlled Sequential Memory Allocation", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product manages a group of objects or resources and performs a separate memory allocation for each object, but it does not properly limit the total amount of memory that is consumed by all of the combined objects.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (Memory)"]}], "mitigations": [{"description": "Ensure multiple allocations of the same kind of object are properly tracked - possibly across multiple sessions, requests, or messages. Define an appropriate strategy for handling requests that exceed the limit, and consider supporting a configuration option so that the administrator can extend the ...", "phase": ["Implementation"]}, {"description": "Run the program using system-provided resource limits for memory. This might still cause the program to crash or exit, but the impact to the rest of the system will be minimized.", "phase": ["Operation"]}], "observed_examples": [{"cve": "CVE-2020-36049", "description": "JavaScript-based packet decoder uses concatenation of many small strings, causing out-of-memory (OOM) condition"}, {"cve": "CVE-2019-20176", "description": "Product allocates a new buffer on the stack for each file in a directory, allowing stack exhaustion"}, {"cve": "CVE-2013-1591", "description": "Chain: an integer overflow (CWE-190) in the image size calculation causes an infinite loop (CWE-835) which sequentially allocates buffers without limi..."}], "platforms": {"languages": ["C", "C++", "Not Language-Specific"]}}, "1326": {"name": "Missing Immutable Root of Trust in Hardware", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A missing immutable root of trust in the hardware results in the ability to bypass secure boot or execute untrusted or adversarial boot code.", "consequences": [{"scope": ["Authentication", "Authorization"], "impact": ["Gain Privileges or Assume Identity", "Execute Unauthorized Code or Commands", "Modify Memory"]}], "mitigations": [{"description": "When architecting the system, the RoT should be designated for storage in a memory that does not allow further programming/writes.", "phase": ["Architecture and Design"]}, {"description": "During implementation and test, the RoT memory location should be demonstrated to not allow further programming/writes.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Dynamic Analysis", "description": "Automated testing can verify that RoT components are immutable."}, {"method": "Architecture or Design Review", "description": "Root of trust elements and memory should be part of architecture and design reviews."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Security Hardware", "Not Technology-Specific"]}}, "1327": {"name": "Binding to an Unrestricted IP Address", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product assigns the address 0.0.0.0 for a database server, a cloud service/instance, or any computing resource that communicates remotely.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Amplification"]}], "mitigations": [{"description": "Assign IP addresses that are not 0.0.0.0.", "phase": ["System Configuration"]}, {"description": "Unwanted connections to the configured server may be denied through a firewall or other packet filtering measures.", "phase": ["System Configuration"]}], "observed_examples": [{"cve": "CVE-2022-21947", "description": "Desktop manager for Kubernetes and container management binds a service to 0.0.0.0, allowing users on the network to make requests to a dashboard API."}], "platforms": {"languages": ["Other"], "technologies": ["Web Server", "Client Server", "Cloud Computing"]}}, "1328": {"name": "Security Version Number Mutable to Older Versions", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Security-version number in hardware is mutable, resulting in the ability to downgrade (roll-back) the boot firmware to vulnerable code versions.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Authentication", "Authorization"], "impact": ["Other"]}], "mitigations": [{"description": "When architecting the system, security version data should be designated for storage in registers that are either read-only or have access controls that prevent modification by an untrusted agent.", "phase": ["Architecture and Design"]}, {"description": "During implementation and test, security version data should be demonstrated to be read-only and access controls should be validated.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Dynamic Analysis", "description": "Mutability of stored security version numbers and programming with older firmware images should be part of automated testing."}, {"method": "Architecture or Design Review", "description": "Anti-roll-back features should be reviewed as part of Architecture or Design review."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Security Hardware", "Not Technology-Specific"]}}, "1329": {"name": "Reliance on Component That is Not Updateable", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains a component that cannot be updated or patched in order to remove vulnerabilities or significant bugs.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Access Control", "Authentication", "Authorization", "Other"], "impact": ["Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Execute Unauthorized Code or Commands", "DoS: Crash, Exit, or Restart", "Quality Degradation", "Reduce Maintainability"]}], "mitigations": [{"description": "Specify requirements that each component should be updateable, including ROM, firmware, etc.", "phase": ["Requirements"]}, {"description": "Design the product to allow for updating of its components. Include the external infrastructure that might be necessary to support updates, such as distribution servers.", "phase": ["Architecture and Design"]}, {"description": "With hardware, support patches that can be programmed in-field or during manufacturing through hardware fuses. This feature can be used for limited patching of devices after shipping, or for the next batch of silicon devices manufactured, without changing the full device ROM.", "phase": ["Architecture and Design", "Implementation"]}], "detection_methods": [{"method": "Architecture or Design Review", "description": "Check the consumer or maintainer documentation, the architecture/design documentation, or the original requirements to ensure that the documentation includes details for how to update the firmware."}], "observed_examples": [{"cve": "CVE-2020-9054", "description": "Chain: network-attached storage (NAS) device has a critical OS command injection (CWE-78) vulnerability that is actively exploited to place IoT device..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "ICS/OT"]}}, "1330": {"name": "Remanent Data Readable after Memory Erase", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Confidential information stored in memory circuits is readable or recoverable after being cleared or erased.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Modify Memory", "Read Memory"]}], "detection_methods": [{"method": "Architecture or Design Review"}, {"method": "Dynamic Analysis with Manual Results Interpretation"}], "observed_examples": [{"cve": "CVE-2019-8575", "description": "Firmware Data Deletion Vulnerability in which a base station factory reset might not delete all user information. The impact of this enables a new own..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Security Hardware", "Not Technology-Specific"]}}, "1331": {"name": "Improper Isolation of Shared Resources in Network On Chip (NoC)", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The Network On Chip (NoC) does not isolate or incorrectly isolates its on-chip-fabric and internal resources such that they are shared between trusted and untrusted agents, creating timing channels.", "consequences": [{"scope": ["Confidentiality", "Availability"], "impact": ["DoS: Resource Consumption (Other)", "Varies by Context", "Other"]}], "mitigations": [{"description": "Implement priority-based arbitration inside the NoC and have dedicated buffers or virtual channels for routing secret data from trusted agents.", "phase": ["Architecture and Design", "Implementation"]}], "detection_methods": [{"method": "Manual Analysis", "description": "Providing marker flags to send through the interfaces coupled with examination of which users are able to read or manipulate the flags will help verify that the proper isolation has been achieved and ..."}], "observed_examples": [{"cve": "CVE-2021-33096", "description": "Improper isolation of shared resource in a network-on-chip leads to denial of service"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Security Hardware", "Not Technology-Specific"]}}, "1332": {"name": "Improper Handling of Faults that Lead to Instruction Skips", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The device is missing or incorrectly implements circuitry or sensors that detect and mitigate the skipping of security-critical CPU instructions when they occur.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Authentication"], "impact": ["Bypass Protection Mechanism", "Alter Execution Logic", "Unexpected State"]}], "mitigations": [{"description": "Design strategies for ensuring safe failure if\n                        inputs, such as Vcc, are modified out of acceptable\n                        ranges.", "phase": ["Architecture and Design"]}, {"description": "Design strategies for ensuring safe behavior if\n                        instructions attempt to be skipped.", "phase": ["Architecture and Design"]}, {"description": "Identify mission critical secrets that should\n                          be wiped if faulting is detected, and design a\n                          mechanism to do the deletion.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "This weakness can be found using automated static analysis once a developer has indicated which code paths are critical to protect."}, {"method": "Simulation / Emulation", "description": "This weakness can be found using automated dynamic analysis. Both emulation of a CPU with instruction skips, as well as RTL simulation of a CPU IP, can indicate parts of the code that are sensitive to..."}, {"method": "Manual Analysis", "description": "This weakness can be found using manual (static) analysis. The analyst has security objectives that are matched against the high-level code. This method is less precise than emulation, especially if t..."}], "observed_examples": [{"cve": "CVE-2019-15894", "description": "fault injection attack bypasses the verification mode, potentially allowing arbitrary code execution."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip"]}}, "1333": {"name": "Inefficient Regular Expression Complexity", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.", "extended_description": "Some regular expression engines have a feature called \"backtracking\". If the token cannot match, the engine \"backtracks\" to a position that may result in a different token that can match.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)"]}], "mitigations": [{"description": "Use regular expressions that do not support backtracking, e.g. by removing nested quantifiers.", "phase": ["Architecture and Design"]}, {"description": "Set backtracking limits in the configuration of the regular expression implementation, such as PHP's pcre.backtrack_limit. Also consider limits on execution time for the process.", "phase": ["System Configuration"]}, {"description": "Do not use regular expressions with untrusted input. If regular expressions must be used, avoid using backtracking in the expression.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2020-5243", "description": "server allows ReDOS with crafted User-Agent strings, due to overlapping capture groups that cause excessive backtracking."}, {"cve": "CVE-2021-21317", "description": "npm package for user-agent parser prone to ReDoS due to overlapping capture groups"}, {"cve": "CVE-2019-16215", "description": "Markdown parser uses inefficient regex when processing a message, allowing users to cause CPU consumption and delay preventing processing of other mes..."}, {"cve": "CVE-2019-6785", "description": "Long string in a version control product allows DoS due to an inefficient regex."}, {"cve": "CVE-2019-12041", "description": "Javascript code allows ReDoS via a long string due to excessive backtracking."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1334": {"name": "Unauthorized Error Injection Can Degrade Hardware Redundancy", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "An unauthorized agent can inject errors into a redundant block to deprive the system of redundancy or put the system in a degraded operating mode.", "consequences": [{"scope": ["Integrity", "Availability"], "impact": ["DoS: Crash, Exit, or Restart", "DoS: Instability", "Quality Degradation", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Resource Consumption (Other)", "Reduce Performance", "Reduce Reliability", "Unexpected State"]}], "mitigations": [{"description": "Ensure the design does not allow error injection in modes intended for normal run-time operation. Provide access controls on interfaces for injecting errors.", "phase": ["Architecture and Design"]}, {"description": "Disallow error injection in modes which are expected to be used for normal run-time operation. Provide access controls on interfaces for injecting errors.", "phase": ["Implementation"]}, {"description": "Add an access control layer atop any unprotected interfaces for injecting errors.", "phase": ["Integration"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1335": {"name": "Incorrect Bitwise Shift of Integer", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "An integer value is specified to be shifted by a negative amount or an amount greater than or equal to the number of bits contained in the value causing an unexpected or indeterminate result.", "consequences": [{"scope": ["Integrity"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Implicitly or explicitly add checks and mitigation for negative or over-shift values.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2009-4307", "description": "An unexpected large value in the ext4 filesystem causes an overshift condition resulting in a divide by zero."}, {"cve": "CVE-2012-2100", "description": "An unexpected large value in the ext4 filesystem causes an overshift condition resulting in a divide by zero - fix of CVE-2009-4307."}, {"cve": "CVE-2020-8835", "description": "An overshift in a kernel allowed out of bounds reads and writes resulting in a root takeover."}, {"cve": "CVE-2015-1607", "description": "Program is not properly handling signed bitwise left-shifts causing an overlapping memcpy memory range error."}, {"cve": "CVE-2016-9842", "description": "Compression function improperly executes a signed left shift of a negative integer."}], "platforms": {"languages": ["C", "C++", "C#", "Java", "JavaScript"], "technologies": ["Not Technology-Specific"]}}, "1336": {"name": "Improper Neutralization of Special Elements Used in a Template Engine", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.", "consequences": [{"scope": ["Integrity"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Choose a template engine that offers a sandbox or restricted mode, or at least limits the power of any available expressions, function calls, or commands.", "phase": ["Architecture and Design"]}, {"description": "Use the template engine's sandbox or restricted mode, if available.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2024-34359", "description": "Chain: Python bindings for LLM\n\t\t\t\t\tlibrary do not use a sandboxed environment when\n\t\t\t\t\tparsing a template and constructing a prompt,\n\t\t\t\t\tallowing j..."}, {"cve": "CVE-2017-16783", "description": "server-side template injection in content management server"}, {"cve": "CVE-2020-9437", "description": "authentication / identity management product has client-side template injection"}, {"cve": "CVE-2020-12790", "description": "Server-Side Template Injection using a Twig template"}, {"cve": "CVE-2021-21244", "description": "devops platform allows SSTI"}], "platforms": {"languages": ["Java", "PHP", "Python", "JavaScript", "Interpreted"], "technologies": ["Not Technology-Specific", "AI/ML", "Client Server"]}}, "1338": {"name": "Improper Protections Against Hardware Overheating", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A hardware device is missing or has inadequate protection features to prevent overheating.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (Other)"]}], "mitigations": [{"description": "Temperature maximum and minimum limits should be enforced using thermal sensors both in silicon and at the platform level.", "phase": ["Architecture and Design"]}, {"description": "The platform should support cooling solutions such as fans that can be modulated based on device-operation needs to maintain a stable temperature.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Dynamic Analysis with Manual Results Interpretation", "description": "Dynamic tests should be performed to stress-test temperature controls."}, {"method": "Architecture or Design Review", "description": "Power management controls should be part of Architecture and Design reviews."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "ICS/OT", "Power Management Hardware", "Processor Hardware"]}}, "1339": {"name": "Insufficient Precision or Accuracy of a Real Number", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product processes a real number with an implementation in which the number's representation does not preserve required accuracy and precision in its fractional part, causing an incorrect result.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Integrity"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Confidentiality", "Availability", "Access Control"], "impact": ["Read Application Data", "Modify Application Data"]}], "mitigations": [{"description": "The developer or maintainer can move to a more accurate representation of real numbers.  In extreme cases, the programmer can move to representations such as ratios of BigInts which can represent real numbers to extremely fine precision. The programmer can also use the concept of an Unum real. The m...", "phase": ["Implementation", "Patching and Maintenance"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2018-16069", "description": "Chain: series of floating-point precision errors\n\t\t\t(CWE-1339) in a web browser rendering engine causes out-of-bounds read\n\t\t\t(CWE-125), giving access..."}, {"cve": "CVE-2017-7619", "description": "Chain: rounding error in floating-point calculations\n\t\t\t(CWE-1339) in image processor leads to infinite loop (CWE-835)"}, {"cve": "CVE-2021-29529", "description": "Chain: machine-learning product can have a heap-based\n\t\t\tbuffer overflow (CWE-122) when some integer-oriented bounds are\n\t\t\tcalculated by using ceilin..."}, {"cve": "CVE-2008-2108", "description": "Chain: insufficient precision (CWE-1339) in\n\t\t\trandom-number generator causes some zero bits to be reliably\n\t\t\tgenerated, reducing the amount of entro..."}, {"cve": "CVE-2006-6499", "description": "Chain: web browser crashes due to infinite loop - \"bad\n\t\t\tlooping logic [that relies on] floating point math [CWE-1339] to exit\n\t\t\tthe loop [CWE-835]\""}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "134": {"name": "Use of Externally-Controlled Format String", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a function that accepts a format string as an argument, but the format string originates from an external source.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}, {"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Modify Memory", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Choose a language that is not subject to this flaw.", "phase": ["Requirements"]}, {"description": "Ensure that all format string functions are passed a static string which cannot be controlled by the user, and that the proper number of arguments are always sent to that function as well. If at all possible, use functions that do not support the %n operator in format strings. [REF-116] [REF-117]", "phase": ["Implementation"]}, {"description": "Run compilers and linkers with high warning levels, since they may detect incorrect usage.", "phase": ["Build and Compilation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "This weakness can often be detected using automated static analysis tools. Many modern tools use data flow analysis or constraint-based techniques to minimize the number of false positives."}, {"method": "Black Box", "description": "Since format strings often occur in rarely-occurring erroneous conditions (e.g. for error message logging), they can be difficult to detect using black box methods. It is highly likely that many laten..."}, {"method": "Automated Static Analysis - Binary or Bytecode"}], "observed_examples": [{"cve": "CVE-2002-1825", "description": "format string in Perl program"}, {"cve": "CVE-2001-0717", "description": "format string in bad call to syslog function"}, {"cve": "CVE-2002-0573", "description": "format string in bad call to syslog function"}, {"cve": "CVE-2002-1788", "description": "format strings in NNTP server responses"}, {"cve": "CVE-2006-2480", "description": "Format string vulnerability exploited by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename."}], "platforms": {"languages": ["Not Language-Specific", "C", "C++", "Perl"]}}, "1341": {"name": "Multiple Releases of Same Resource or Handle", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product attempts to close or release a resource or handle more than once, without any successful open between the close operations.", "consequences": [{"scope": ["Availability", "Integrity"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Change the code's logic so that the resource is only closed once. This might require simplifying or refactoring. This fix can be simple to do in small code blocks, but more difficult when multiple closes are buried within complex conditionals.", "phase": ["Implementation"]}, {"description": "It can be effective to implement a flag that is (1) set when the resource is opened, (2) cleared when it is closed, and (3) checked before closing. This approach can be useful when there are disparate cases in which closes must be performed. However, flag-tracking can increase code complexity and re...", "phase": ["Implementation"]}, {"description": "When closing a resource, set the resource's associated variable to NULL or equivalent value for the given language. Some APIs will ignore this null value without causing errors. For other APIs, this can lead to application crashes or exceptions, which may still be preferable to corrupting an uninten...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "For commonly-used APIs and resource types, automated tools often have signatures that can spot this issue."}, {"method": "Automated Dynamic Analysis", "description": "Some compiler instrumentation tools such as AddressSanitizer (ASan) can indirectly detect some instances of this weakness."}], "observed_examples": [{"cve": "CVE-2019-13351", "description": "file descriptor double close can cause the wrong file to be associated with a file descriptor."}, {"cve": "CVE-2006-5051", "description": "Chain: Signal handler contains too much functionality (CWE-828), introducing a race condition (CWE-362) that leads to a double free (CWE-415)."}, {"cve": "CVE-2004-0772", "description": "Double free resultant from certain error conditions."}], "platforms": {"languages": ["Java", "Rust", "Not Language-Specific", "C", "C++"], "technologies": ["Not Technology-Specific"]}}, "1342": {"name": "Information Exposure through Microarchitectural State after Transient Execution", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The processor does not properly clear microarchitectural state after incorrect microcode assists or speculative execution, resulting in transient execution.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Modify Memory", "Read Memory", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Hardware ensures that no illegal data flows from faulting micro-ops exists at the microarchitectural level.", "phase": ["Architecture and Design", "Requirements"]}, {"description": "Include instructions that explicitly remove traces of unneeded computations from software interactions with microarchitectural elements e.g. lfence, sfence, mfence, clflush.", "phase": ["Build and Compilation"]}], "observed_examples": [{"cve": "CVE-2020-0551", "description": "Load value injection in some processors utilizing speculative execution may allow an authenticated user to enable information disclosure via a side-ch..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "System on Chip"]}}, "135": {"name": "Incorrect Calculation of Multi-Byte String Length", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not correctly calculate the length of strings that can contain wide or multi-byte characters.", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Availability", "Confidentiality"], "impact": ["Read Memory", "DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)"]}, {"scope": ["Confidentiality"], "impact": ["Read Memory"]}], "mitigations": [{"description": "Always verify the length of the string unit character.", "phase": ["Implementation"]}, {"description": "Use length computing functions (e.g. strlen, wcslen, etc.) appropriately with their equivalent type (e.g.: byte, wchar_t, etc.)", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C", "C++"]}}, "1351": {"name": "Improper Handling of Hardware Behavior in Exceptionally Cold Environments", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A hardware device, or the firmware running on it, is\n                missing or has incorrect protection features to maintain\n                goals of security primitives when the device is cooled below\n                standard operating temperatures.", "consequences": [{"scope": ["Integrity", "Authentication"], "impact": ["Varies by Context", "Unexpected State"]}], "mitigations": [{"description": "The system should account for security primitive behavior when cooled outside standard temperatures.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip"]}}, "1357": {"name": "Reliance on Insufficiently Trustworthy Component", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product is built from multiple separate components, but it uses a component that is not sufficiently trusted to meet expectations for security, reliability, updateability, and maintainability.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "mitigations": [{"description": "For each component, ensure that its supply chain is well-controlled with sub-tier suppliers using best practices. For third-party software components such as libraries, ensure that they are developed and actively maintained by reputable vendors.", "phase": ["Requirements", "Architecture and Design", "Implementation"]}, {"description": "Maintain a Bill of Materials for all components and sub-components of the product. For software, maintain a Software Bill of Materials (SBOM). According to [REF-1247], \"An SBOM is a formal, machine-readable inventory of software components and dependencies, information about those components, and th...", "phase": ["Architecture and Design", "Implementation", "Integration", "Manufacturing"]}, {"description": "Continue to monitor changes in each of the product's components, especially when the changes indicate new vulnerabilities, end-of-life (EOL) plans, supplier practices that affect trustworthiness, etc.", "phase": ["Operation", "Patching and Maintenance"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2020-9054", "description": "Chain: network-attached storage (NAS) device has a critical OS command injection (CWE-78) vulnerability that is actively exploited to place IoT device..."}], "platforms": {"technologies": ["Not Technology-Specific", "ICS/OT"]}}, "138": {"name": "Improper Neutralization of Special Elements", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as control elements or syntactic markers when they are sent to a downstream component.", "extended_description": "Most languages and protocols have their own special elements such as characters and reserved words. These special elements can carry control implications. If product does not prevent external control or influence over the inclusion of such special elements, the control flow of the program may be altered from what was intended. For example, both Unix and Windows interpret the symbol < (\"less than\") as meaning \"read input from a file\".", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Other"], "impact": ["Execute Unauthorized Code or Commands", "Alter Execution Logic", "DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Developers should anticipate that special elements (e.g. delimiters, symbols) will be injected into input vectors of their product. One defense is to create an allowlist (e.g. a regular expression) that defines valid input according to the requirements specifications. Strictly filter any input that ...", "phase": ["Implementation"]}, {"description": "Use and specify an appropriate output encoding to ensure that the special elements are well-defined. A normal byte sequence in one encoding could be a special element in another.", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2001-0677", "description": "Read arbitrary files from mail client by providing a special MIME header that is internally used to store pathnames for attachments."}, {"cve": "CVE-2000-0703", "description": "Setuid program does not cleanse special escape sequence before sending data to a mail program, causing the mail program to process those sequences."}, {"cve": "CVE-2003-0020", "description": "Multi-channel issue. Terminal escape sequences not filtered from log files."}, {"cve": "CVE-2003-0083", "description": "Multi-channel issue. Terminal escape sequences not filtered from log files."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1384": {"name": "Improper Handling of Physical or Environmental Conditions", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not properly handle unexpected physical or environmental conditions that occur naturally or are artificially induced.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Varies by Context", "Unexpected State"]}], "mitigations": [{"description": "In requirements, be specific about expectations for how the product will perform when it exceeds physical and environmental boundary conditions, e.g., by shutting down.", "phase": ["Requirements"]}, {"description": "Where possible, include independent components that can detect excess environmental conditions and have the capability to shut down the product.", "phase": ["Architecture and Design", "Implementation"]}, {"description": "Where possible, use shielding or other materials that can increase the adversary's workload and reduce the likelihood of being able to successfully trigger a security-related failure.", "phase": ["Architecture and Design", "Implementation"]}], "observed_examples": [{"cve": "CVE-2019-17391", "description": "Lack of anti-glitch protections allows an attacker to launch a physical attack to bypass the secure boot and read protected eFuses."}], "platforms": {"technologies": ["System on Chip", "ICS/OT"]}}, "1385": {"name": "Missing Origin Validation in WebSockets", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a WebSocket, but it does not properly verify that the source of data or communication is valid.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Non-Repudiation", "Access Control"], "impact": ["Varies by Context", "Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Read Application Data", "Modify Application Data", "DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Enable CORS-like access restrictions by verifying the 'Origin' header during the WebSocket handshake.", "phase": ["Implementation"]}, {"description": "Use a randomized CSRF token to verify requests.", "phase": ["Implementation"]}, {"description": "Use TLS to securely communicate using 'wss' (WebSocket Secure) instead of 'ws'.", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2020-25095", "description": "web console for SIEM product does not check Origin header, allowing Cross Site WebSocket Hijacking (CSWH)"}, {"cve": "CVE-2018-6651", "description": "Chain: gaming client attempts to validate the Origin header, but only uses a substring, allowing Cross-Site WebSocket hijacking by forcing requests fr..."}, {"cve": "CVE-2018-14730", "description": "WebSocket server does not check the origin of requests, allowing attackers to steal developer's code using a ws://127.0.0.1:3123/ connection."}, {"cve": "CVE-2018-14731", "description": "WebSocket server does not check the origin of requests, allowing attackers to steal developer's code using a ws://127.0.0.1/ connection to a randomize..."}, {"cve": "CVE-2018-14732", "description": "WebSocket server does not check the origin of requests, allowing attackers to steal developer's code using a ws://127.0.0.1:8080/ connection."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "1386": {"name": "Insecure Operation on Windows Junction / Mount Point", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product opens a file or directory, but it does not properly prevent the name from being associated with a junction or mount point to a destination that is outside of the intended control sphere.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Files or Directories"]}, {"scope": ["Integrity"], "impact": ["Modify Files or Directories"]}, {"scope": ["Availability"], "impact": ["Modify Files or Directories"]}], "mitigations": [{"description": "When designing software that will have different rights than the executer, the software should check that files that it is interacting with are not improper hard links or mount points.  One way to do this in Windows is to use the functionality embedded in the following command: \"dir /al /s /b\" or, i...", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2021-26426", "description": "Privileged service allows attackers to delete unauthorized files using a directory junction, leading to arbitrary code execution as SYSTEM."}, {"cve": "CVE-2020-0863", "description": "By creating a mount point and hard links, an attacker can abuse a service to allow users arbitrary file read permissions."}, {"cve": "CVE-2019-1161", "description": "Chain: race condition (CWE-362) in anti-malware product allows deletion of files by creating a junction (CWE-1386) and using hard links during the tim..."}, {"cve": "CVE-2014-0568", "description": "Escape from sandbox for document reader by using a mountpoint [REF-1264]"}], "platforms": {"languages": ["Not Language-Specific"]}}, "1389": {"name": "Incorrect Parsing of Numbers with Different Radices", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product parses numeric input assuming base 10 (decimal) values, but it does not account for inputs that use a different base number (radix).", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Integrity"], "impact": ["Bypass Protection Mechanism", "Alter Execution Logic"]}], "mitigations": [{"description": "If only decimal-based values are expected in the application, conditional checks should be created in a way that prevent octal or hexadecimal strings from being checked. This can be achieved by converting any numerical string to an explicit base-10 integer prior to the conditional check, to prevent ...", "phase": ["Implementation"]}, {"description": "If various numerical bases do need to be supported, check for leading values indicating the non-decimal base you wish to support (such as 0x for hex) and convert the numeric strings to integers of the respective base. Reject any other alternative-base string that is not intentionally supported by th...", "phase": ["Implementation"]}, {"description": "If regular expressions are used to validate IP addresses, ensure that they are bounded using ^ and $ to prevent base-prepended IP addresses from being matched.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2021-29662", "description": "Chain: Use of zero-prepended IP addresses in Perl-based IP validation module can lead to an access control bypass."}, {"cve": "CVE-2021-28918", "description": "Chain: Use of zero-prepended IP addresses in a product that manages IP blocks can lead to an SSRF."}, {"cve": "CVE-2021-29921", "description": "Chain: Use of zero-prepended IP addresses in a Python standard library package can lead to an SSRF."}, {"cve": "CVE-2021-29923", "description": "Chain: Use of zero-prepended IP addresses in the net Golang library can lead to an access control bypass."}, {"cve": "CVE-2021-29424", "description": "Chain: Use of zero-prepended IP addresses in Perl netmask module allows bypass of IP-based access control."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1390": {"name": "Weak Authentication", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability", "Access Control"], "impact": ["Read Application Data", "Gain Privileges or Assume Identity", "Execute Unauthorized Code or Commands"]}], "observed_examples": [{"cve": "CVE-2024-48445", "description": "Chain: e-commerce app relies on an easily-guessable timestamp (CWE-341) in a weak authentication algorithm (CWE-1390)"}, {"cve": "CVE-2022-30034", "description": "Chain: Web UI for a Python RPC framework does not use regex anchors to validate user login emails (CWE-777), potentially allowing bypass of OAuth (CWE..."}, {"cve": "CVE-2022-35248", "description": "Chat application skips validation when Central Authentication Service\n\t\t  (CAS) is enabled, effectively removing the second factor from\n\t\t  two-factor..."}, {"cve": "CVE-2021-3116", "description": "Chain: Python-based HTTP Proxy server uses the wrong boolean operators (CWE-480) causing an  incorrect comparison (CWE-697) that identifies an authN f..."}, {"cve": "CVE-2022-29965", "description": "Distributed Control System (DCS) uses a deterministic algorithm to generate utility passwords"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["ICS/OT", "Not Technology-Specific"]}}, "1391": {"name": "Use of Weak Credentials", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "When the user changes or sets a password, check\n\t  the password against a database of already compromised or\n\t  breached passwords. These passwords are likely to be used in\n\t  password guessing attacks.", "phase": ["Architecture and Design", "Operation"]}], "observed_examples": [{"cve": "[REF-1374]", "description": "Chain: JavaScript-based cryptocurrency library can fall back to the insecure Math.random() function instead of reporting a failure (CWE-392), thus red..."}, {"cve": "CVE-2022-30270", "description": "Remote Terminal Unit (RTU) uses default credentials for some SSH accounts"}, {"cve": "CVE-2022-29965", "description": "Distributed Control System (DCS) uses a deterministic algorithm to generate utility passwords"}, {"cve": "CVE-2022-30271", "description": "Remote Terminal Unit (RTU) uses a hard-coded SSH private key that is likely to be used in typical deployments"}, {"cve": "CVE-2021-38759", "description": "microcontroller board has default password, allowing admin access"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["ICS/OT", "Not Technology-Specific"]}}, "1392": {"name": "Use of Default Credentials", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.", "extended_description": "It is common practice for products to be designed to use\n\tdefault keys, passwords, or other mechanisms for\n\tauthentication.  The rationale is to simplify the\n\tmanufacturing process or the system administrator's task of\n\tinstallation and deployment into an enterprise. However, if\n\tadmins do not change the defaults, it is easier for attackers\n\tto bypass authentication quickly across multiple\n\torganizations.", "consequences": [{"scope": ["Authentication"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Prohibit use of default, hard-coded, or other values that do not vary for each installation of the product - especially for separate organizations.", "phase": ["Requirements"]}, {"description": "Force the administrator to change the credential upon installation.", "phase": ["Architecture and Design"]}, {"description": "The product administrator could change the defaults upon installation or during operation.", "phase": ["Installation", "Operation"]}], "observed_examples": [{"cve": "CVE-2022-30270", "description": "Remote Terminal Unit (RTU) uses default credentials for some SSH accounts"}, {"cve": "CVE-2021-41192", "description": "data visualization/sharing package uses default secret keys or cookie values if they are not specified in environment variables"}, {"cve": "CVE-2021-38759", "description": "microcontroller board has default password, allowing admin access"}, {"cve": "CVE-2018-3825", "description": "cloud cluster management product has a default master encryption key"}, {"cve": "CVE-2010-2306", "description": "Intrusion Detection System (IDS) uses the same static, private SSL keys for multiple devices and installations, allowing decryption of SSL traffic"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["ICS/OT", "Not Technology-Specific"]}}, "1393": {"name": "Use of Default Password", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses default passwords for potentially critical functionality.", "extended_description": "It is common practice for products to be designed to use\n\tdefault passwords for authentication.  The rationale is to\n\tsimplify the manufacturing process or the system\n\tadministrator's task of installation and deployment into an\n\tenterprise. However, if admins do not change the defaults,\n\tthen it makes it easier for attackers to quickly bypass\n\tauthentication across multiple organizations. There are many\n\tlists of default passwords and default-password scanning tools\n\tthat are easily available fr...", "consequences": [{"scope": ["Authentication"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Prohibit use of default, hard-coded, or other values that do not vary for each installation of the product - especially for separate organizations.", "phase": ["Requirements"]}, {"description": "Ensure that product documentation clearly emphasizes the presence of default passwords and provides steps for the administrator to change them.", "phase": ["Documentation"]}, {"description": "Force the administrator to change the credential upon installation.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2022-30270", "description": "Remote Terminal Unit (RTU) uses default credentials for some SSH accounts"}, {"cve": "CVE-2022-2336", "description": "OPC Unified Architecture (OPC UA) industrial automation product has a default password"}, {"cve": "CVE-2021-38759", "description": "microcontroller board has default password, allowing admin access"}, {"cve": "CVE-2021-44480", "description": "children's smart watch has default passwords allowing attackers to send SMS commands and listen to the device's surroundings"}, {"cve": "CVE-2020-11624", "description": "surveillance camera has default password for the admin account"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "ICS/OT"]}}, "1394": {"name": "Use of Default Cryptographic Key", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a default cryptographic key for potentially critical functionality.", "extended_description": "It is common practice for products to be designed to use\n\tdefault keys.  The rationale is to simplify the manufacturing\n\tprocess or the system administrator's task of installation and\n\tdeployment into an enterprise. However, if admins do not\n\tchange the defaults, it is easier for attackers to bypass\n\tauthentication quickly across multiple organizations.", "consequences": [{"scope": ["Authentication"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Prohibit use of default, hard-coded, or other values that do not vary for each installation of the product - especially for separate organizations.", "phase": ["Requirements"]}, {"description": "Force the administrator to change the credential upon installation.", "phase": ["Architecture and Design"]}, {"description": "The product administrator could change the defaults upon installation or during operation.", "phase": ["Installation", "Operation"]}], "observed_examples": [{"cve": "CVE-2018-3825", "description": "cloud cluster management product has a default master encryption key"}, {"cve": "CVE-2016-1561", "description": "backup storage product has a default SSH public key in the authorized_keys file, allowing root access"}, {"cve": "CVE-2010-2306", "description": "Intrusion Detection System (IDS) uses the same static, private SSL keys for multiple devices and installations, allowing decryption of SSL traffic"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1395": {"name": "Dependency on Vulnerable Third-Party Component", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product has a dependency on a third-party component that contains one or more known vulnerabilities.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "In some industries such as healthcare [REF-1320] [REF-1322] or technologies such as the cloud [REF-1321], it might be unclear about who is responsible for applying patches for third-party vulnerabilities: the vendor, the operator/customer, or a separate service. Clarifying roles and responsibilities...", "phase": ["Requirements", "Policy"]}, {"description": "Require a Bill of Materials for all components and sub-components of the product. For software, require a Software Bill of Materials (SBOM) [REF-1247] [REF-1311].", "phase": ["Requirements"]}, {"description": "Maintain a Bill of Materials for all components and sub-components of the product. For software, maintain a Software Bill of Materials (SBOM). According to [REF-1247], \"An SBOM is a formal, machine-readable inventory of software components and dependencies, information about those components, and th...", "phase": ["Architecture and Design", "Implementation", "Integration", "Manufacturing"]}], "detection_methods": [{"method": "Automated Analysis", "description": "For software, use Software Composition Analysis (SCA) tools, which automatically analyze products to identify third-party dependencies. Often, SCA tools can be used to link with known vulnerabilities ..."}], "observed_examples": [{"cve": "CVE-2025-45612", "description": "product uses a vulnerable version of an authentication framework, allowing authentication bypass"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "14": {"name": "Compiler Removal of Code to Clear Buffers", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Sensitive memory is cleared according to the source code, but compiler optimizations leave the memory untouched when it is not read from again, aka \"dead store removal.\"", "consequences": [{"scope": ["Confidentiality", "Access Control"], "impact": ["Read Memory", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Store the sensitive data in a \"volatile\" memory location if available.", "phase": ["Implementation"]}, {"description": "If possible, configure your compiler so that it does not remove dead stores.", "phase": ["Build and Compilation"]}, {"description": "Where possible, encrypt sensitive data that are used by a software system.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Black Box", "description": "This specific weakness is impossible to detect using black box methods. While an analyst could examine memory to see that it has not been scrubbed, an analysis of the executable would not be successfu..."}, {"method": "White Box", "description": "This weakness is only detectable using white box methods (see black box detection factor). Careful analysis is required to determine if the code is likely to be removed by the compiler."}], "platforms": {"languages": ["C", "C++", "Compiled"]}}, "140": {"name": "Improper Neutralization of Delimiters", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not neutralize or incorrectly neutralizes delimiters.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that delimiters will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system.", "phase": ["Implementation"]}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2003-0307", "description": "Attacker inserts field separator into input to specify admin privileges."}, {"cve": "CVE-2000-0293", "description": "Multiple internal space, insufficient quoting - program does not use proper delimiter between values."}, {"cve": "CVE-2001-0527", "description": "Attacker inserts carriage returns and \"|\" field separator characters to add new user/privileges."}, {"cve": "CVE-2002-0267", "description": "Linebreak in field of PHP script allows admin privileges when written to data file."}], "platforms": {"languages": ["Not Language-Specific"]}}, "141": {"name": "Improper Neutralization of Parameter/Argument Delimiters", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as parameter or argument delimiters when they are sent to a downstream component.", "extended_description": "As data is parsed, an injected/absent/malformed delimiter may cause the process to take unexpected actions.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that parameter/argument delimiters will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2003-0307", "description": "Attacker inserts field separator into input to specify admin privileges."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1419": {"name": "Incorrect Initialization of Resource", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product attempts to initialize a resource but does not correctly do so, which might leave the resource in an unexpected, incorrect, or insecure state when it is accessed.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory", "Read Application Data", "Unexpected State"]}, {"scope": ["Authorization", "Integrity"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Choose the safest-possible initialization for security-related resources.", "phase": ["Implementation"]}, {"description": "Ensure that each resource (whether variable, memory buffer, register, etc.) is fully initialized.", "phase": ["Implementation"]}, {"description": "Pay close attention to complex conditionals or reset sources   that affect initialization, since some paths might not perform the initialization.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2020-27211", "description": "Chain: microcontroller system-on-chip uses a register value stored in flash to set product protection state on the memory bus and does not contain pro..."}, {"cve": "CVE-2023-25815", "description": "chain: a change in an underlying package causes the gettext function to use implicit initialization with a hard-coded path (CWE-1419) under the user-w..."}, {"cve": "CVE-2022-43468", "description": "WordPress module sets internal variables based on external inputs, allowing false reporting of the number of views"}, {"cve": "CVE-2022-36349", "description": "insecure default variable initialization in BIOS firmware for a hardware board allows DoS"}, {"cve": "CVE-2015-7763", "description": "distributed filesystem only initializes part of the variable-length padding for a packet, allowing attackers to read sensitive information from previo..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "142": {"name": "Improper Neutralization of Value Delimiters", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as value delimiters when they are sent to a downstream component.", "extended_description": "As data is parsed, an injected/absent/malformed delimiter may cause the process to take unexpected actions.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that value delimiters will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2000-0293", "description": "Multiple internal space, insufficient quoting - program does not use proper delimiter between values."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1420": {"name": "Exposure of Sensitive Information during Transient Execution", "abstraction": "Base", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "A processor event or prediction may allow incorrect operations (or correct operations with incorrect data) to execute transiently, potentially exposing data over a covert channel.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}], "mitigations": [{"description": "The hardware designer can attempt to prevent transient execution from causing observable discrepancies in specific covert channels.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Manual Analysis"}, {"method": "Fuzzing"}, {"method": "Fuzzing"}], "observed_examples": [{"cve": "CVE-2017-5753", "description": "Microarchitectural conditional branch predictors may allow operations to execute transiently after a misprediction, potentially exposing data over a c..."}, {"cve": "CVE-2021-0089", "description": "A machine clear triggered by self-modifying code may allow incorrect operations to execute transiently, potentially exposing data over a covert channe..."}, {"cve": "CVE-2022-0002", "description": "Microarchitectural indirect branch predictors may allow incorrect operations to execute transiently after a misprediction, potentially exposing data o..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1421": {"name": "Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A processor event may allow transient operations to access\n\t\t\tarchitecturally restricted data (for example, in another address\n\t\t\tspace) in a shared microarchitectural structure (for example, a CPU\n\t\t\tcache), potentially exposing the data over a covert channel.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}], "detection_methods": [{"method": "Manual Analysis"}, {"method": "Automated Analysis"}, {"method": "Automated Analysis"}], "observed_examples": [{"cve": "CVE-2017-5715", "description": "A fault may allow transient user-mode operations to\n\t\t\t\taccess kernel data cached in the L1D, potentially exposing the data\n\t\t\t\tover a covert channel."}, {"cve": "CVE-2018-3615", "description": "A fault may allow transient non-enclave operations to\n\t\t\t\taccess SGX enclave data cached in the L1D, potentially exposing the\n\t\t\t\tdata over a covert c..."}, {"cve": "CVE-2019-1135", "description": "A TSX Asynchronous Abort may allow transient operations\n\t\t\t\tto access architecturally restricted data, potentially exposing the\n\t\t\t\tdata over a covert..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1422": {"name": "Exposure of Sensitive Information caused by Incorrect Data Forwarding during Transient Execution", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A processor event or prediction may allow incorrect or stale data to\n\t\t  be forwarded to transient operations, potentially exposing data over a\n\t\t  covert channel.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}], "detection_methods": [{"method": "Automated Static Analysis"}, {"method": "Manual Analysis"}, {"method": "Automated Analysis"}], "observed_examples": [{"cve": "CVE-2020-0551", "description": "A fault, microcode assist, or abort may allow transient\n\t\t\t\tload operations to forward malicious stale data to dependent\n\t\t\t\toperations executed by a ..."}, {"cve": "CVE-2020-8698", "description": "A fast store forwarding predictor may allow store\n\t\t\t\toperations to forward incorrect data to transient load operations,\n\t\t\t\tpotentially exposing data..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1423": {"name": "Exposure of Sensitive Information caused by Shared Microarchitectural Predictor State that Influences Transient Execution", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Shared microarchitectural predictor state may allow code to influence\n\t\t\t\ttransient execution across a hardware boundary, potentially exposing\n\t\t\t\tdata that is accessible beyond the boundary over a covert channel.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}], "detection_methods": [{"method": "Manual Analysis"}, {"method": "Automated Analysis"}, {"method": "Automated Analysis"}], "observed_examples": [{"cve": "CVE-2017-5754", "description": "(Branch Target Injection, BTI, Spectre v2). Shared\n\t\t\t\t\tmicroarchitectural indirect branch predictor state may allow code to\n\t\t\t\t\tinfluence transient ..."}, {"cve": "CVE-2022-0001", "description": "(Branch History Injection, BHI, Spectre-BHB). Shared\n\t\t\t\t\tbranch history state may allow user-mode code to influence transient\n\t\t\t\t\texecution in the k..."}, {"cve": "CVE-2021-33149", "description": "(RSB underflow, Retbleed). Shared return stack buffer\n\t\t\t\t\tstate may allow code that executes before a prediction barrier to\n\t\t\t\t\tinfluence transient ..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Microcontroller Hardware", "Processor Hardware", "Memory Hardware", "System on Chip"]}}, "1426": {"name": "Improper Validation of Generative AI Output", "abstraction": "Base", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product invokes a generative AI/ML\n\t\t\tcomponent whose behaviors and outputs cannot be directly\n\t\t\tcontrolled, but the product does not validate or\n\t\t\tinsufficiently validates the outputs to ensure that they\n\t\t\talign with the intended security, content, or privacy\n\t\t\tpolicy.", "consequences": [{"scope": ["Integrity"], "impact": ["Execute Unauthorized Code or Commands", "Varies by Context"]}], "mitigations": [{"description": "Since the output from a generative AI component (such as an LLM) cannot be trusted, ensure that it operates in an untrusted or non-privileged space.", "phase": ["Architecture and Design"]}, {"description": "Use \"semantic comparators,\" which are mechanisms that\n\t\t\t\t\tprovide semantic comparison to identify objects that might appear\n\t\t\t\t\tdifferent but are semantically similar.", "phase": ["Operation"]}], "detection_methods": [{"method": "Dynamic Analysis with Manual Results Interpretation", "description": "Use known techniques for prompt injection\n\t\t\t and other attacks, and adjust the attacks to be more\n\t\t\t specific to the model or system."}, {"method": "Dynamic Analysis with Automated Results Interpretation", "description": "Use known techniques for prompt injection\n\t\t\t and other attacks, and adjust the attacks to be more\n\t\t\t specific to the model or system."}, {"method": "Architecture or Design Review", "description": "Review of the product design can be\n\t\t\t effective, but it works best in conjunction with dynamic\n\t\t\t analysis."}], "observed_examples": [{"cve": "CVE-2024-3402", "description": "chain: GUI for ChatGPT API performs\n\t\t\t\t\tinput validation but does not properly \"sanitize\"\n\t\t\t\t\tor validate model output data (CWE-1426), leading\n\t\t\t\t..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["AI/ML", "Not Technology-Specific"]}}, "1427": {"name": "Improper Neutralization of Input Used for LLM Prompting", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses externally-provided data to build prompts provided to\nlarge language models (LLMs), but the way these prompts are constructed\ncauses the LLM to fail to distinguish between user-supplied inputs and\ndeveloper provided system directives.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands", "Varies by Context"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Integrity"], "impact": ["Modify Application Data", "Execute Unauthorized Code or Commands"]}, {"scope": ["Access Control"], "impact": ["Read Application Data", "Modify Application Data", "Gain Privileges or Assume Identity"]}], "detection_methods": [{"method": "Dynamic Analysis with Manual Results Interpretation"}, {"method": "Dynamic Analysis with Automated Results Interpretation"}, {"method": "Architecture or Design Review"}], "observed_examples": [{"cve": "CVE-2023-32786", "description": "Chain: LLM integration framework has prompt injection\n\t\t\t\t(CWE-1427) that allows an attacker to force the service to retrieve\n\t\t\t\tdata from an arbitra..."}, {"cve": "CVE-2024-5184", "description": "ML-based email analysis product uses an\n\t\t\t\tAPI service that allows a malicious user to inject a\n\t\t\t\tdirect prompt and take over the service logic, fo..."}, {"cve": "CVE-2024-5565", "description": "Chain: library for generating SQL via LLMs using RAG uses\n\t\t\t\ta prompt function to present the user with visualized results,\n\t\t\t\tallowing altering of ..."}, {"cve": "CVE-2024-48746", "description": "AI-based integration with business intel dashboard allows prompt injection through its natural language component, allowing execution of arbitrary cod..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["AI/ML"]}}, "1428": {"name": "Reliance on HTTP instead of HTTPS", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product provides or relies on use of HTTP communications when HTTPS is available.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data"]}], "mitigations": [{"description": "Explicitly require HTTPS or another mechanism that ensures that communication is encrypted [REF-1464].", "phase": ["Architecture and Design"]}, {"description": "Avoid using \"mixed content,\" i.e., serving a web page over HTTPS in which the page includes elements that use \"http:\" URLs [REF-1466] [REF-1467]. This is often done for images or other resources that do not seem to have privacy or security implications.", "phase": ["Implementation"]}, {"description": "Perform \"HTTPS forcing,\" that is, redirecting HTTP requests to HTTPS.", "phase": ["Implementation", "Operation"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "1429": {"name": "Missing Security-Relevant Feedback for Unexecuted Operations in Hardware Interface", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product has a hardware interface that silently discards operations\n\t\t\tin situations for which feedback would be security-relevant, such as\n\t\t\tthe timely detection of failures or attacks.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory", "Read Files or Directories"]}, {"scope": ["Integrity"], "impact": ["Modify Memory", "Modify Files or Directories"]}, {"scope": ["Availability"], "impact": ["DoS: Resource Consumption (Memory)", "DoS: Crash, Exit, or Restart"]}], "detection_methods": [{"method": "Automated Static Analysis - Source Code"}, {"method": "Manual Static Analysis - Source Code"}], "observed_examples": [{"cve": "[REF-1468]", "description": "Open source silicon root of trust (RoT) product does not immediately report when an integrity check fails for memory requests, causing the product to ..."}], "platforms": {"languages": ["C", "C++", "Verilog", "Hardware Description Language", "Not Language-Specific"], "technologies": ["Security Hardware", "Processor Hardware", "Microcontroller Hardware", "System on Chip"]}}, "143": {"name": "Improper Neutralization of Record Delimiters", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as record delimiters when they are sent to a downstream component.", "extended_description": "As data is parsed, an injected/absent/malformed delimiter may cause the process to take unexpected actions.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that record delimiters will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2004-1982", "description": "Carriage returns in subject field allow adding new records to data file."}, {"cve": "CVE-2001-0527", "description": "Attacker inserts carriage returns and \"|\" field separator characters to add new user/privileges."}], "platforms": {"languages": ["Not Language-Specific"]}}, "1431": {"name": "Driving Intermediate Cryptographic State/Results to Hardware Module Outputs", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a hardware module implementing a cryptographic\n\t\t  algorithm that writes sensitive information about the intermediate\n\t\t  state or results of its cryptographic operations via one of its output\n\t\t  wires (typically the output port containing the final result).", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory", "Read Application Data"]}], "detection_methods": [{"method": "Automated Static Analysis - Source Code"}, {"method": "Simulation / Emulation"}, {"method": "Formal Verification"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["System on Chip"]}}, "1434": {"name": "Insecure Setting of Generative AI/ML Model Inference Parameters", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product has a component that relies on a\n\t  generative AI/ML model configured with inference parameters that\n\t  produce an unacceptably high rate of erroneous or unexpected\n\t  outputs.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Varies by Context", "Unexpected State"]}, {"scope": ["Other"], "impact": ["Alter Execution Logic", "Unexpected State", "Varies by Context"]}], "mitigations": [{"description": "Develop and adhere to robust parameter tuning\n\t\t\tprocesses that include extensive testing and\n\t\t\tvalidation.", "phase": ["Implementation", "System Configuration", "Operation"]}, {"description": "Implement feedback mechanisms to continuously\n\t\t\tassess and adjust model performance.", "phase": ["Implementation", "System Configuration", "Operation"]}, {"description": "Provide comprehensive documentation and\n\t\t\tguidelines for parameter settings to ensure consistent and\n\t\t\taccurate model behavior.", "phase": ["Documentation"]}], "detection_methods": [{"method": "Automated Dynamic Analysis", "description": "Manipulate inference parameters and perform\n            comparative evaluation to assess the impact of selected\n            values. Build a suite of systems using targeted tools that\n            detec..."}, {"method": "Manual Dynamic Analysis", "description": "Manipulate inference parameters and perform\n            comparative evaluation to assess the impact of selected\n            values. Build a suite of systems using targeted tools that\n            detec..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["AI/ML", "Not Technology-Specific"]}}, "144": {"name": "Improper Neutralization of Line Delimiters", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as line delimiters when they are sent to a downstream component.", "extended_description": "As data is parsed, an injected/absent/malformed delimiter may cause the process to take unexpected actions.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that line delimiters will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-0267", "description": "Linebreak in field of PHP script allows admin privileges when written to data file."}], "platforms": {"languages": ["Not Language-Specific"]}}, "145": {"name": "Improper Neutralization of Section Delimiters", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as section delimiters when they are sent to a downstream component.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that section delimiters will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "146": {"name": "Improper Neutralization of Expression/Command Delimiters", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as expression or command delimiters when they are sent to a downstream component.", "extended_description": "As data is parsed, an injected/absent/malformed delimiter may cause the process to take unexpected actions.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Other"], "impact": ["Execute Unauthorized Code or Commands", "Alter Execution Logic"]}], "mitigations": [{"description": "Developers should anticipate that inter-expression and inter-command delimiters will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "147": {"name": "Improper Neutralization of Input Terminators", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as input terminators when they are sent to a downstream component.", "extended_description": "For example, a \".\" in SMTP signifies the end of mail message data, whereas a null character can be used for the end of a string.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that terminators will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2000-0319", "description": "MFV. mail server does not properly identify terminator string to signify end of message, causing corruption, possibly in conjunction with off-by-one e..."}, {"cve": "CVE-2000-0320", "description": "MFV. mail server does not properly identify terminator string to signify end of message, causing corruption, possibly in conjunction with off-by-one e..."}, {"cve": "CVE-2001-0996", "description": "Mail server does not quote end-of-input terminator if it appears in the middle of a message."}, {"cve": "CVE-2002-0001", "description": "Improperly terminated comment or phrase allows commands."}], "platforms": {"languages": ["Not Language-Specific"]}}, "148": {"name": "Improper Neutralization of Input Leaders", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly handle when a leading character or sequence (\"leader\") is missing or malformed, or if multiple leaders are used when only one should be allowed.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that leading characters will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "149": {"name": "Improper Neutralization of Quoting Syntax", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Quotes injected into a product can be used to compromise a system. As data are parsed, an injected/absent/duplicate/malformed use of quotes may cause the process to take unexpected actions.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that quotes will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2004-0956", "description": "Database allows remote attackers to cause a denial of service (application crash) via a MATCH AGAINST query with an opening double quote but no closin..."}, {"cve": "CVE-2003-1016", "description": "MIE. MFV too? bypass AV/security with fields that should not be quoted, duplicate quotes, missing leading/trailing quotes."}], "platforms": {"languages": ["Not Language-Specific"]}}, "15": {"name": "External Control of System or Configuration Setting", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "One or more system settings or configuration elements can be externally controlled by a user.", "extended_description": "Allowing external control of system settings can disrupt service or cause an application to behave in unexpected, and potentially malicious ways.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Because setting manipulation covers a diverse set of functions, any attempt at illustrating it will inevitably be incomplete. Rather than searching for a tight-knit relationship between the functions addressed in the setting manipulation category, take a step back and consider the sorts of system va...", "phase": ["Implementation", "Architecture and Design"]}, {"description": "In general, do not allow user-provided or otherwise untrusted data to control sensitive values. The leverage that an attacker gains by controlling these values is not always immediately obvious, but do not underestimate the creativity of the attacker.", "phase": ["Implementation", "Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"technologies": ["Not Technology-Specific", "ICS/OT"]}}, "150": {"name": "Improper Neutralization of Escape, Meta, or Control Sequences", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.", "extended_description": "As data is parsed, an injected/absent/malformed delimiter may cause the process to take unexpected actions.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that escape, meta and control characters/sequences will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2002-0542", "description": "The mail program processes special \"~\" escape sequence even when not in interactive mode."}, {"cve": "CVE-2000-0703", "description": "Setuid program does not filter escape sequences before calling mail program."}, {"cve": "CVE-2002-0986", "description": "Mail function does not filter control characters from arguments, allowing mail message content to be modified."}, {"cve": "CVE-2003-0020", "description": "Multi-channel issue. Terminal escape sequences not filtered from log files."}, {"cve": "CVE-2003-0083", "description": "Multi-channel issue. Terminal escape sequences not filtered from log files."}], "platforms": {"languages": ["Not Language-Specific"]}}, "151": {"name": "Improper Neutralization of Comment Delimiters", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as comment delimiters when they are sent to a downstream component.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that comments will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-0001", "description": "Mail client command execution due to improperly terminated comment in address list."}, {"cve": "CVE-2004-0162", "description": "MIE. RFC822 comment fields may be processed as other fields by clients."}, {"cve": "CVE-2004-1686", "description": "Well-placed comment bypasses security warning."}, {"cve": "CVE-2005-1909", "description": "Information hiding using a manipulation involving injection of comment code into product. Note: these vulnerabilities are likely vulnerable to more ge..."}, {"cve": "CVE-2005-1969", "description": "Information hiding using a manipulation involving injection of comment code into product. Note: these vulnerabilities are likely vulnerable to more ge..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "152": {"name": "Improper Neutralization of Macro Symbols", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as macro symbols when they are sent to a downstream component.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that macro symbols will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system.", "phase": ["Implementation"]}, {"description": "Use and specify an output encoding that can be handled by the downstream component that is reading the output. Common encodings include ISO-8859-1, UTF-7, and UTF-8. When an encoding is not specified, a downstream component may choose a different encoding, either by assuming a default encoding or au...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-0770", "description": "Server trusts client to expand macros, allows macro characters to be expanded to trigger resultant information exposure."}, {"cve": "CVE-2008-2018", "description": "Attacker can obtain sensitive information from a database by using a comment containing a macro, which inserts the data during expansion."}], "platforms": {"languages": ["Not Language-Specific"]}}, "153": {"name": "Improper Neutralization of Substitution Characters", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as substitution characters when they are sent to a downstream component.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that substitution characters will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-0770", "description": "Server trusts client to expand macros, allows macro characters to be expanded to trigger resultant information exposure."}], "platforms": {"languages": ["Not Language-Specific"]}}, "154": {"name": "Improper Neutralization of Variable Name Delimiters", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as variable name delimiters when they are sent to a downstream component.", "extended_description": "As data is parsed, an injected delimiter may cause the process to take unexpected actions that result in an attack. Example: \"$\" for an environment variable.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that variable name delimiters will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2005-0129", "description": "\"%\" variable is expanded by wildcard function into disallowed commands."}, {"cve": "CVE-2002-0770", "description": "Server trusts client to expand macros, allows macro characters to be expanded to trigger resultant information exposure."}], "platforms": {"languages": ["Not Language-Specific"]}}, "155": {"name": "Improper Neutralization of Wildcards or Matching Symbols", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as wildcards or matching symbols when they are sent to a downstream component.", "extended_description": "As data is parsed, an injected element may cause the process to take unexpected actions.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that wildcard or matching elements will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2002-0433", "description": "List files in web server using \"*.ext\""}, {"cve": "CVE-2002-1010", "description": "Bypass file restrictions using wildcard character."}, {"cve": "CVE-2001-0334", "description": "Wildcards generate long string on expansion."}, {"cve": "CVE-2004-1962", "description": "SQL injection involving \"/**/\" sequences."}], "platforms": {"languages": ["Not Language-Specific"]}}, "156": {"name": "Improper Neutralization of Whitespace", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as whitespace when they are sent to a downstream component.", "extended_description": "This can include space, tab, etc.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that whitespace will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-0637", "description": "MIE. virus protection bypass with RFC violations involving extra whitespace, or missing whitespace."}, {"cve": "CVE-2004-0942", "description": "CPU consumption with MIME headers containing lines with many space characters, probably due to algorithmic complexity (RESOURCE.AMP.ALG)."}, {"cve": "CVE-2003-1015", "description": "MIE. whitespace interpreted differently by mail clients."}], "platforms": {"languages": ["Not Language-Specific"]}}, "157": {"name": "Failure to Sanitize Paired Delimiters", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly handle the characters that are used to mark the beginning and ending of a group of entities, such as parentheses, brackets, and braces.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that grouping elements will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2004-0956", "description": "Crash via missing paired delimiter (open double-quote but no closing double-quote)."}, {"cve": "CVE-2000-1165", "description": "Crash via message without closing \">\"."}, {"cve": "CVE-2005-2933", "description": "Buffer overflow via mailbox name with an opening double quote but missing a closing double quote, causing a larger copy than expected."}], "platforms": {"languages": ["Not Language-Specific"]}}, "158": {"name": "Improper Neutralization of Null Byte or NUL Character", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes NUL characters or null bytes when they are sent to a downstream component.", "extended_description": "As data is parsed, an injected NUL character or null byte may cause the product to believe the input is terminated earlier than it actually is, or otherwise cause the input to be misinterpreted. This could then be used to inject potentially dangerous input that occurs after the null byte or otherwise bypass validation routines and other protection mechanisms.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that null characters or null bytes will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2008-1284", "description": "NUL byte in theme name causes directory traversal impact to be worse"}, {"cve": "CVE-2005-2008", "description": "Source code disclosure using trailing null."}, {"cve": "CVE-2005-3293", "description": "Source code disclosure using trailing null."}, {"cve": "CVE-2005-2061", "description": "Trailing null allows file include."}, {"cve": "CVE-2002-1774", "description": "Null character in MIME header allows detection bypass."}], "platforms": {"languages": ["Not Language-Specific", "C", "C++"], "technologies": ["Not Technology-Specific"]}}, "159": {"name": "Improper Handling of Invalid Use of Special Elements", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not properly filter, remove, quote, or otherwise manage the invalid use of special elements in user-controlled input, which could cause adverse effect on its behavior and integrity.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that special elements will be injected/removed/manipulated in the input vectors of their software system. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-1362", "description": "Crash via message type without separator character"}, {"cve": "CVE-2000-0116", "description": "Extra \"<\" in front of SCRIPT tag bypasses XSS prevention."}], "platforms": {"languages": ["Not Language-Specific"]}}, "160": {"name": "Improper Neutralization of Leading Special Elements", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes leading special elements that could be interpreted in unexpected ways when they are sent to a downstream component.", "extended_description": "As data is parsed, improperly handled leading special elements may cause the process to take unexpected actions that result in an attack.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that leading special elements will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-1345", "description": "Multiple FTP clients write arbitrary files via absolute paths in server responses"}], "platforms": {"languages": ["Not Language-Specific"]}}, "161": {"name": "Improper Neutralization of Multiple Leading Special Elements", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes multiple leading special elements that could be interpreted in unexpected ways when they are sent to a downstream component.", "extended_description": "As data is parsed, improperly handled multiple leading special elements may cause the process to take unexpected actions that result in an attack.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that multiple leading special elements will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-1238", "description": "Server allows remote attackers to bypass access restrictions for files via an HTTP request with a sequence of multiple / (slash) characters such as ht..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "162": {"name": "Improper Neutralization of Trailing Special Elements", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes trailing special elements that could be interpreted in unexpected ways when they are sent to a downstream component.", "extended_description": "As data is parsed, improperly handled trailing special elements may cause the process to take unexpected actions that result in an attack.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that trailing special elements will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2004-0847", "description": "web framework for .NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) \"\\\" (..."}, {"cve": "CVE-2002-1451", "description": "Trailing space (\"+\" in query string) leads to source code disclosure."}, {"cve": "CVE-2001-0446", "description": "Application server allows remote attackers to read source code for .jsp files by appending a / to the requested URL."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "163": {"name": "Improper Neutralization of Multiple Trailing Special Elements", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes multiple trailing special elements that could be interpreted in unexpected ways when they are sent to a downstream component.", "extended_description": "As data is parsed, improperly handled multiple trailing special elements may cause the process to take unexpected actions that result in an attack.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that multiple trailing special elements will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-1078", "description": "Directory listings in web server using multiple trailing slash"}, {"cve": "CVE-2004-0281", "description": "Multiple trailing dot allows directory listing"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "164": {"name": "Improper Neutralization of Internal Special Elements", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes internal special elements that could be interpreted in unexpected ways when they are sent to a downstream component.", "extended_description": "As data is parsed, improperly handled internal special elements may cause the process to take unexpected actions that result in an attack.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that internal special elements will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "165": {"name": "Improper Neutralization of Multiple Internal Special Elements", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes multiple internal special elements that could be interpreted in unexpected ways when they are sent to a downstream component.", "extended_description": "As data is parsed, improperly handled multiple internal special elements may cause the process to take unexpected actions that result in an attack.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that multiple internal special elements will be injected/removed/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "166": {"name": "Improper Handling of Missing Special Element", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not handle or incorrectly handles when an expected special element is missing.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Developers should anticipate that special elements will be removed in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-1362", "description": "Crash via message type without separator character"}, {"cve": "CVE-2002-0729", "description": "Missing special character (separator) causes crash"}, {"cve": "CVE-2002-1532", "description": "HTTP GET without \\r\\n\\r\\n CRLF sequences causes product to wait indefinitely and prevents other users from accessing it"}], "platforms": {"languages": ["Not Language-Specific"]}}, "167": {"name": "Improper Handling of Additional Special Element", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not handle or incorrectly handles when an additional unexpected special element is provided.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Developers should anticipate that extra special elements will be injected in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2000-0116", "description": "Extra \"<\" in front of SCRIPT tag bypasses XSS prevention."}, {"cve": "CVE-2001-1157", "description": "Extra \"<\" in front of SCRIPT tag."}, {"cve": "CVE-2002-2086", "description": "\"<script\" - probably a cleansing error"}], "platforms": {"languages": ["Not Language-Specific"]}}, "168": {"name": "Improper Handling of Inconsistent Special Elements", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly handle input in which an inconsistency exists between two or more special characters or reserved words.", "extended_description": "An example of this problem would be if paired characters appear in the wrong order, or if the special characters are not properly nested.", "consequences": [{"scope": ["Availability", "Access Control", "Non-Repudiation"], "impact": ["DoS: Crash, Exit, or Restart", "Bypass Protection Mechanism", "Hide Activities"]}], "mitigations": [{"description": "Developers should anticipate that inconsistent special elements will be injected/manipulated in the input vectors of their product. Use an appropriate combination of denylists and allowlists to ensure only valid, expected and appropriate input is processed by the system."}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "170": {"name": "Improper Null Termination", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.", "extended_description": "Null termination errors frequently occur in two different ways. An off-by-one error could cause a null to be written out of bounds, leading to an overflow. Or, a program could use a strncpy() function call incorrectly, which prevents a null terminator from being added at all. Other scenarios are possible.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Read Memory", "Execute Unauthorized Code or Commands"]}, {"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["DoS: Crash, Exit, or Restart", "Read Memory", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)"]}, {"scope": ["Integrity", "Availability"], "impact": ["Modify Memory", "DoS: Crash, Exit, or Restart"]}, {"scope": ["Integrity", "Confidentiality", "Availability", "Access Control", "Other"], "impact": ["Alter Execution Logic", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Use a language that is not susceptible to these issues. However, be careful of null byte interaction errors (CWE-626) with lower-level constructs that may be written in a language that is susceptible.", "phase": ["Requirements"]}, {"description": "Ensure that all string functions used are understood fully as to how they append null characters. Also, be wary of off-by-one errors when appending nulls to the end of strings.", "phase": ["Implementation"]}, {"description": "If performance constraints permit, special code can be added that validates null-termination of string buffers, this is a rather naive and error-prone solution.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2000-0312", "description": "Attacker does not null-terminate argv[] when invoking another program."}, {"cve": "CVE-2003-0777", "description": "Interrupted step causes resultant lack of null termination."}, {"cve": "CVE-2004-1072", "description": "Fault causes resultant lack of null termination, leading to buffer expansion."}, {"cve": "CVE-2001-1389", "description": "Multiple vulnerabilities related to improper null termination."}, {"cve": "CVE-2003-0143", "description": "Product does not null terminate a message buffer after snprintf-like call, leading to overflow."}], "platforms": {"languages": ["C", "C++"]}}, "172": {"name": "Encoding Error", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not properly encode or decode the data, resulting in unexpected values.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "While it is risky to use dynamically-generated query strings, code, or commands that mix control and data together, sometimes it may be unavoidable. Properly quote arguments and escape any special characters within those arguments. The most conservative approach is to escape or filter all characters...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2004-1315", "description": "Forum software improperly URL decodes the highlight parameter when extracting text to highlight, which allows remote attackers to execute arbitrary PH..."}, {"cve": "CVE-2004-1939", "description": "XSS protection mechanism attempts to remove \"/\" that could be used to close tags, but it can be bypassed using double encoded slashes (%252F)"}, {"cve": "CVE-2001-0709", "description": "Server allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode."}, {"cve": "CVE-2005-2256", "description": "Hex-encoded path traversal variants - \"%2e%2e\", \"%2e%2e%2f\", \"%5c%2e%2e\""}], "platforms": {"languages": ["Not Language-Specific"]}}, "173": {"name": "Improper Handling of Alternate Encoding", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly handle when an input uses an alternate encoding that is valid for the control sphere to which the input is being sent.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Avoid making decisions based on names of resources (e.g. files) if those resources can have alternate names.", "phase": ["Architecture and Design"]}, {"description": "Use and specify an output encoding that can be handled by the downstream component that is reading the output. Common encodings include ISO-8859-1, UTF-7, and UTF-8. When an encoding is not specified, a downstream component may choose a different encoding, either by assuming a default encoding or au...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "174": {"name": "Double Decoding of the Same Data", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product decodes the same input twice, which can limit the effectiveness of any protection mechanism that occurs in between the decoding operations.", "consequences": [{"scope": ["Access Control", "Confidentiality", "Availability", "Integrity", "Other"], "impact": ["Bypass Protection Mechanism", "Execute Unauthorized Code or Commands", "Varies by Context"]}], "mitigations": [{"description": "Avoid making decisions based on names of resources (e.g. files) if those resources can have alternate names.", "phase": ["Architecture and Design"]}, {"description": "Use and specify an output encoding that can be handled by the downstream component that is reading the output. Common encodings include ISO-8859-1, UTF-7, and UTF-8. When an encoding is not specified, a downstream component may choose a different encoding, either by assuming a default encoding or au...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2004-1315", "description": "Forum software improperly URL decodes the highlight parameter when extracting text to highlight, which allows remote attackers to execute arbitrary PH..."}, {"cve": "CVE-2004-1939", "description": "XSS protection mechanism attempts to remove \"/\" that could be used to close tags, but it can be bypassed using double encoded slashes (%252F)"}, {"cve": "CVE-2001-0333", "description": "Directory traversal using double encoding."}, {"cve": "CVE-2004-1938", "description": "\"%2527\" (double-encoded single quote) used in SQL injection."}, {"cve": "CVE-2005-1945", "description": "Double hex-encoded data."}], "platforms": {"languages": ["Not Language-Specific"]}}, "175": {"name": "Improper Handling of Mixed Encoding", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly handle when the same input uses several different (mixed) encodings.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Avoid making decisions based on names of resources (e.g. files) if those resources can have alternate names.", "phase": ["Architecture and Design"]}, {"description": "Use and specify an output encoding that can be handled by the downstream component that is reading the output. Common encodings include ISO-8859-1, UTF-7, and UTF-8. When an encoding is not specified, a downstream component may choose a different encoding, either by assuming a default encoding or au...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "176": {"name": "Improper Handling of Unicode Encoding", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly handle when an input contains Unicode encoding.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Avoid making decisions based on names of resources (e.g. files) if those resources can have alternate names.", "phase": ["Architecture and Design"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2000-0884", "description": "Server allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain Uni..."}, {"cve": "CVE-2001-0709", "description": "Server allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode."}, {"cve": "CVE-2001-0669", "description": "Overlaps interaction error."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "177": {"name": "Improper Handling of URL Encoding (Hex Encoding)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly handle when all or part of an input has been URL encoded.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Avoid making decisions based on names of resources (e.g. files) if those resources can have alternate names.", "phase": ["Architecture and Design"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2000-0900", "description": "Hex-encoded path traversal variants - \"%2e%2e\", \"%2e%2e%2f\", \"%5c%2e%2e\""}, {"cve": "CVE-2005-2256", "description": "Hex-encoded path traversal variants - \"%2e%2e\", \"%2e%2e%2f\", \"%5c%2e%2e\""}, {"cve": "CVE-2004-2121", "description": "Hex-encoded path traversal variants - \"%2e%2e\", \"%2e%2e%2f\", \"%5c%2e%2e\""}, {"cve": "CVE-2004-0280", "description": "\"%20\" (encoded space)"}, {"cve": "CVE-2003-0424", "description": "\"%20\" (encoded space)"}], "platforms": {"languages": ["Not Language-Specific"]}}, "178": {"name": "Improper Handling of Case Sensitivity", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Avoid making decisions based on names of resources (e.g. files) if those resources can have alternate names.", "phase": ["Architecture and Design"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2000-0499", "description": "Application server allows attackers to bypass execution of a jsp page and read the source code using an upper case JSP extension in the request."}, {"cve": "CVE-2000-0497", "description": "The server is case sensitive, so filetype handlers treat .jsp and .JSP as different extensions. JSP source code may be read because .JSP defaults to t..."}, {"cve": "CVE-2000-0498", "description": "The server is case sensitive, so filetype handlers treat .jsp and .JSP as different extensions. JSP source code may be read because .JSP defaults to t..."}, {"cve": "CVE-2001-0766", "description": "A URL that contains some characters whose case is not matched by the server's filters may bypass access restrictions because the case-insensitive file..."}, {"cve": "CVE-2001-0795", "description": "Server allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "179": {"name": "Incorrect Behavior Order: Early Validation", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product validates input before applying protection mechanisms that modify the input, which could allow an attacker to bypass the validation via dangerous inputs that only arise after the modification.", "extended_description": "Product needs to validate data at the proper time, after data has been canonicalized and cleansed. Early validation is susceptible to various manipulations that result in dangerous inputs that are produced by canonicalization and cleansing.", "consequences": [{"scope": ["Access Control", "Integrity"], "impact": ["Bypass Protection Mechanism", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-0433", "description": "List files in web server using \"*.ext\""}, {"cve": "CVE-2003-0332", "description": "Product modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authenticati..."}, {"cve": "CVE-2002-0802", "description": "Database consumes an extra character when processing a character that cannot be converted, which could remove an escape character from the query and m..."}, {"cve": "CVE-2000-0191", "description": "Overlaps \"fakechild/../realchild\""}, {"cve": "CVE-2004-2363", "description": "Product checks URI for \"<\" and other literal characters, but does it before hex decoding the URI, so \"%3E\" and other sequences are allowed."}], "platforms": {"languages": ["Not Language-Specific"]}}, "180": {"name": "Incorrect Behavior Order: Validate Before Canonicalize", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product validates input before it is canonicalized, which prevents the product from detecting data that becomes invalid after the canonicalization step.", "extended_description": "This can be used by an attacker to bypass the validation and launch attacks that expose weaknesses that would otherwise be prevented, such as injection.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-0433", "description": "List files in web server using \"*.ext\""}, {"cve": "CVE-2003-0332", "description": "Product modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authenticati..."}, {"cve": "CVE-2002-0802", "description": "Database consumes an extra character when processing a character that cannot be converted, which could remove an escape character from the query and m..."}, {"cve": "CVE-2000-0191", "description": "Overlaps \"fakechild/../realchild\""}, {"cve": "CVE-2004-2363", "description": "Product checks URI for \"<\" and other literal characters, but does it before hex decoding the URI, so \"%3E\" and other sequences are allowed."}], "platforms": {"languages": ["Not Language-Specific"]}}, "181": {"name": "Incorrect Behavior Order: Validate Before Filter", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product validates data before it has been filtered, which prevents the product from detecting data that becomes invalid after the filtering step.", "extended_description": "This can be used by an attacker to bypass the validation and launch attacks that expose weaknesses that would otherwise be prevented, such as injection.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being filtered.", "phase": ["Implementation", "Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2002-0934", "description": "Directory traversal vulnerability allows remote attackers to read or modify arbitrary files via invalid characters between two . (dot) characters, whi..."}, {"cve": "CVE-2003-0282", "description": "Directory traversal vulnerability allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filte..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "182": {"name": "Collapse of Data into Unsafe Value", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product filters data in a way that causes it to be reduced or \"collapsed\" into an unsafe value that violates an expected security property.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Avoid making decisions based on names of resources (e.g. files) if those resources can have alternate names.", "phase": ["Architecture and Design"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}, {"description": "Canonicalize the name to match that of the file system's representation of the name. This can sometimes be achieved with an available API (e.g. in Win32 the GetFullPathName function)."}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2004-0815", "description": "\"/.////\" in pathname collapses to absolute path."}, {"cve": "CVE-2005-3123", "description": "\"/.//..//////././\" is collapsed into \"/.././\" after \"..\" and \"//\" sequences are removed."}, {"cve": "CVE-2002-0325", "description": "\".../...//\" collapsed to \"...\" due to removal of \"./\" in web server."}, {"cve": "CVE-2002-0784", "description": "chain: HTTP server protects against \"..\" but allows \".\" variants such as \"////./../.../\". If the server removes \"/..\" sequences, the result would coll..."}, {"cve": "CVE-2005-2169", "description": "MFV. Regular expression intended to protect against directory traversal reduces \".../...//\" to \"../\"."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "183": {"name": "Permissive List of Allowed Inputs", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2019-12799", "description": "chain: bypass of untrusted deserialization issue (CWE-502) by using an assumed-trusted class (CWE-183)"}, {"cve": "CVE-2019-10458", "description": "sandbox bypass using a method that is on an allowlist"}, {"cve": "CVE-2017-1000095", "description": "sandbox bypass using unsafe methods that are on an allowlist"}, {"cve": "CVE-2019-10458", "description": "CI/CD pipeline feature has unsafe elements in allowlist, allowing bypass of script restrictions"}, {"cve": "CVE-2017-1000095", "description": "Default allowlist includes unsafe methods, allowing bypass of sandbox"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "184": {"name": "Incomplete List of Disallowed Inputs", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Do not rely exclusively on detecting disallowed inputs.  There are too many variants to encode a character, especially when different environments are used, so there is a high likelihood of missing some variants.  Only use detection of disallowed inputs as a mechanism for detecting suspicious activi...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Black Box", "description": "Exploitation of a vulnerability with commonly-used manipulations might fail, but minor variations might succeed."}], "observed_examples": [{"cve": "CVE-2024-6091", "description": "Chain: AI agent platform does not restrict pathnames containing internal \"/./\" sequences (CWE-55), leading to an incomplete denylist (CWE-184) that do..."}, {"cve": "CVE-2024-4315", "description": "Chain: API for text generation using Large Language Models (LLMs) does\n\t\t\t   not include the \"\\\" Windows folder separator in its denylist (CWE-184)\n\t\t..."}, {"cve": "CVE-2024-44335", "description": "Chain: filter only checks for some shell-injection characters (CWE-184), enabling OS command injection (CWE-78)"}, {"cve": "CVE-2008-2309", "description": "product uses a denylist to identify potentially dangerous content, allowing attacker to bypass a warning"}, {"cve": "CVE-2005-2782", "description": "PHP remote file inclusion in web application that filters \"http\" and \"https\" URLs, but not \"ftp\"."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "185": {"name": "Incorrect Regular Expression", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product specifies a regular expression in a way that causes data to be improperly matched or compared.", "extended_description": "When the regular expression is used in protection mechanisms such as filtering or validation, this may allow an attacker to bypass the intended restrictions on the incoming data.", "consequences": [{"scope": ["Other"], "impact": ["Unexpected State", "Varies by Context"]}, {"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Regular expressions can become error prone when defining a complex language even for those experienced in writing grammars. Determine if several smaller regular expressions simplify one large regular expression. Also, subject the regular expression to thorough testing techniques such as equivalence ...", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2002-2109", "description": "Regexp isn't \"anchored\" to the beginning or end, which allows spoofed values that have trusted values as substrings."}, {"cve": "CVE-2005-1949", "description": "Regexp for IP address isn't anchored at the end, allowing appending of shell metacharacters."}, {"cve": "CVE-2001-1072", "description": "Bypass access restrictions via multiple leading slash, which causes a regular expression to fail."}, {"cve": "CVE-2000-0115", "description": "Local user DoS via invalid regular expressions."}, {"cve": "CVE-2002-1527", "description": "chain: Malformed input generates a regular expression error that leads to information exposure."}], "platforms": {"languages": ["Not Language-Specific"]}}, "186": {"name": "Overly Restrictive Regular Expression", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A regular expression is overly restrictive, which prevents dangerous values from being detected.", "extended_description": "This weakness is not about regular expression complexity. Rather, it is about a regular expression that does not match all values that are intended. Consider the use of a regexp to identify acceptable values or to spot unwanted terms. An overly restrictive regexp misses some potentially security-relevant values leading to either false positives *or* false negatives, depending on how the regexp is being used within the code. Consider the expression /[0-8]/ where the intention was /[0-9]/.  This e...", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Regular expressions can become error prone when defining a complex language even for those experienced in writing grammars. Determine if several smaller regular expressions simplify one large regular expression. Also, subject your regular expression to thorough testing techniques such as equivalence...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2005-1604", "description": "MIE. \".php.ns\" bypasses \".php$\" regexp but is still parsed as PHP by Apache. (manipulates an equivalence property under Apache)"}], "platforms": {"languages": ["Not Language-Specific"]}}, "187": {"name": "Partial String Comparison", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product performs a comparison that only examines a portion of a factor before determining whether there is a match, such as a substring, leading to resultant weaknesses.", "extended_description": "For example, an attacker might succeed in authentication by providing a small password that matches the associated portion of the larger, correct password.", "consequences": [{"scope": ["Integrity", "Access Control"], "impact": ["Alter Execution Logic", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Thoroughly test the comparison scheme before deploying code into production. Perform positive testing as well as negative testing.", "phase": ["Testing"]}], "observed_examples": [{"cve": "CVE-2014-6394", "description": "Product does not prevent access to restricted directories due to partial string comparison with a public directory"}, {"cve": "CVE-2004-1012", "description": "Argument parser of an IMAP server treats a partial command \"body[p\" as if it is \"body.peek\", leading to index error and out-of-bounds corruption."}, {"cve": "CVE-2004-0765", "description": "Web browser only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which ..."}, {"cve": "CVE-2002-1374", "description": "One-character password by attacker checks only against first character of real password."}, {"cve": "CVE-2000-0979", "description": "One-character password by attacker checks only against first character of real password."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "188": {"name": "Reliance on Data/Memory Layout", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product makes invalid assumptions about how protocol data or memory is organized at a lower level, resulting in unintended program behavior.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Integrity", "Confidentiality"], "impact": ["Modify Memory", "Read Memory"]}], "mitigations": [{"description": "In flat address space situations, never allow computing memory addresses as offsets from another memory address.", "phase": ["Implementation", "Architecture and Design"]}, {"description": "Fully specify protocol layout unambiguously, providing a structured grammar (e.g., a compilable yacc grammar).", "phase": ["Architecture and Design"]}, {"description": "Testing: Test that the implementation properly handles each case in the protocol grammar.", "phase": ["Testing"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "platforms": {"languages": ["Not Language-Specific", "C", "C++"]}}, "190": {"name": "Integer Overflow or Wraparound", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product performs a calculation that can\n         produce an integer overflow or wraparound when the logic\n         assumes that the resulting value will always be larger than\n         the original value. This occurs when an integer value is\n         incremented to a value that is too large to store in the\n         associated representation. When this occurs, the value may\n         become a very small or negative number.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (Memory)", "DoS: Instability"]}, {"scope": ["Integrity"], "impact": ["Modify Memory"]}, {"scope": ["Confidentiality", "Availability", "Access Control"], "impact": ["Execute Unauthorized Code or Commands", "Bypass Protection Mechanism"]}, {"scope": ["Availability", "Other"], "impact": ["Alter Execution Logic", "DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)"]}, {"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Ensure that all protocols are strictly defined, such that all out-of-bounds behavior can be identified simply, and require strict conformance to the protocol.", "phase": ["Requirements"]}, {"description": "For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-s...", "phase": ["Architecture and Design"]}, {"description": "Examine compiler warnings closely and eliminate problems with potential security implications, such as signed / unsigned mismatch in memory operations, or use of uninitialized variables. Even if the weakness is rarely exploitable, a single failure may lead to the compromise of the entire system.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "This weakness can often be detected using automated static analysis tools. Many modern tools use data flow analysis or constraint-based techniques to minimize the number of false positives."}, {"method": "Black Box", "description": "Sometimes, evidence of this weakness can be detected using dynamic tools and techniques that interact with the product using large test suites with many diverse inputs, such as fuzz testing (fuzzing),..."}, {"method": "Manual Analysis"}], "observed_examples": [{"cve": "CVE-2025-46687", "description": "Chain: Javascript engine code does not perform a length check (CWE-1284) leading to integer overflow (CWE-190) causing allocation of smaller buffer th..."}, {"cve": "CVE-2025-27363", "description": "Font rendering library does not properly\n               handle assigning a signed short value to an unsigned\n               long (CWE-195), leading to..."}, {"cve": "CVE-2021-43537", "description": "Chain: in a web browser, an unsigned 64-bit integer is forcibly cast to a 32-bit integer (CWE-681) and potentially leading to an integer overflow (CWE..."}, {"cve": "CVE-2019-19911", "description": "Chain: Python library does not limit the resources used to process images that specify a very large number of bands (CWE-1284), leading to excessive m..."}, {"cve": "CVE-2022-0545", "description": "Chain: 3D renderer has an integer overflow (CWE-190) leading to write-what-where condition (CWE-123) using a crafted image."}], "platforms": {"languages": ["Not Language-Specific", "C"], "technologies": ["Not Technology-Specific"]}}, "191": {"name": "Integer Underflow (Wrap or Wraparound)", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.", "extended_description": "This can happen in signed and unsigned cases.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Instability"]}, {"scope": ["Integrity"], "impact": ["Modify Memory"]}, {"scope": ["Confidentiality", "Availability", "Access Control"], "impact": ["Execute Unauthorized Code or Commands", "Bypass Protection Mechanism"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2004-0816", "description": "Integer underflow in firewall via malformed packet."}, {"cve": "CVE-2004-1002", "description": "Integer underflow by packet with invalid length."}, {"cve": "CVE-2005-0199", "description": "Long input causes incorrect length calculation."}, {"cve": "CVE-2005-1891", "description": "Malformed icon causes integer underflow in loop counter variable."}], "platforms": {"languages": ["C", "C++", "Java", "C#"]}}, "192": {"name": "Integer Coercion Error", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Integer coercion refers to a set of flaws pertaining to the type casting, extension, or truncation of primitive data types.", "extended_description": "Several flaws fall under the category of integer coercion errors. For the most part, these errors in and of themselves result only in availability and data integrity issues. However, in some circumstances, they may result in other, more complicated security related flaws, such as buffer overflow conditions.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Crash, Exit, or Restart"]}, {"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Integrity", "Other"], "impact": ["Other"]}], "mitigations": [{"description": "A language which throws exceptions on ambiguous data casts might be chosen.", "phase": ["Requirements"]}, {"description": "Design objects and program flow such that multiple or complex casts are unnecessary", "phase": ["Architecture and Design"]}, {"description": "Ensure that any data type casting that you must used is entirely understood in order to reduce the plausibility of error in use.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-2639", "description": "Chain: integer coercion error (CWE-192) prevents a return value from indicating an error, leading to out-of-bounds write (CWE-787)"}], "platforms": {"languages": ["C", "C++", "Java", "C#"]}}, "193": {"name": "Off-by-one Error", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Instability"]}, {"scope": ["Integrity"], "impact": ["Modify Memory"]}, {"scope": ["Confidentiality", "Availability", "Access Control"], "impact": ["Execute Unauthorized Code or Commands", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "When copying character arrays or using character manipulation methods, the correct size parameter must be used to account for the null terminator that needs to be added at the end of the array. Some examples of functions susceptible to this weakness in C include strcpy(), strncpy(), strcat(), strnca...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2003-0252", "description": "Off-by-one error allows remote attackers to cause a denial of service and possibly execute arbitrary code via requests that do not contain newlines."}, {"cve": "CVE-2001-1391", "description": "Off-by-one vulnerability in driver allows users to modify kernel memory."}, {"cve": "CVE-2002-0083", "description": "Off-by-one error allows local users or remote malicious servers to gain privileges."}, {"cve": "CVE-2002-0653", "description": "Off-by-one buffer overflow in function usd by server allows local users to execute arbitrary code as the server user via .htaccess files with long ent..."}, {"cve": "CVE-2002-0844", "description": "Off-by-one buffer overflow in version control system allows local users to execute arbitrary code."}], "platforms": {"languages": ["C", "Not Language-Specific"]}}, "194": {"name": "Unexpected Sign Extension", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product performs an operation on a number that causes it to be sign extended when it is transformed into a larger data type. When the original number is negative, this can produce unexpected values that lead to resultant weaknesses.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability", "Other"], "impact": ["Read Memory", "Modify Memory", "Other"]}], "mitigations": [{"description": "Avoid using signed variables if you don't need to represent negative values. When negative values are needed, perform validation after you save those values to larger data types, or before passing them to functions that are expecting unsigned values.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2018-10887", "description": "Chain: unexpected sign extension (CWE-194) leads to integer overflow (CWE-190), causing an out-of-bounds read (CWE-125)"}, {"cve": "CVE-1999-0234", "description": "Sign extension error produces -1 value that is treated as a command separator, enabling OS command injection."}, {"cve": "CVE-2003-0161", "description": "Product uses \"char\" type for input character. When char is implemented as a signed type, ASCII value 0xFF (255), a sign extension produces a -1 value ..."}, {"cve": "CVE-2007-4988", "description": "chain: signed short width value in image processor is sign extended during conversion to unsigned int, which leads to integer overflow and heap-based ..."}, {"cve": "CVE-2006-1834", "description": "chain: signedness error allows bypass of a length check; later sign extension makes exploitation easier."}], "platforms": {"languages": ["C", "C++"]}}, "195": {"name": "Signed to Unsigned Conversion Error", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a signed primitive and performs a cast to an unsigned primitive, which can produce an unexpected value if the value of the signed primitive can not be represented using an unsigned primitive.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2025-27363", "description": "Font rendering library does not properly\n               handle assigning a signed short value to an unsigned\n               long (CWE-195), leading to..."}, {"cve": "CVE-2007-4268", "description": "Chain: integer signedness error (CWE-195) passes signed comparison, leading to heap overflow (CWE-122)"}], "platforms": {"languages": ["C", "C++"]}}, "196": {"name": "Unsigned to Signed Conversion Error", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses an unsigned primitive and performs a cast to a signed primitive, which can produce an unexpected value if the value of the unsigned primitive can not be represented using a signed primitive.", "extended_description": "Although less frequent an issue than signed-to-unsigned conversion, unsigned-to-signed conversion can be the perfect precursor to dangerous buffer underwrite conditions that allow attackers to move down the stack where they otherwise might not have access in a normal buffer overflow condition. Buffer underwrites occur frequently when large unsigned values are cast to signed values, and then used as indexes into a buffer or for pointer arithmetic.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Integrity"], "impact": ["Modify Memory"]}, {"scope": ["Integrity", "Confidentiality", "Availability", "Access Control"], "impact": ["Execute Unauthorized Code or Commands", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Choose a language which is not subject to these casting flaws.", "phase": ["Requirements"]}, {"description": "Design object accessor functions to implicitly check values for valid sizes. Ensure that all functions which will be used as a size are checked previous to use as a size. If the language permits, throw exceptions rather than using in-band errors.", "phase": ["Architecture and Design"]}, {"description": "Error check the return values of all functions. Be aware of implicit casts made, and use unsigned variables for sizes if at all possible.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C", "C++"]}}, "197": {"name": "Numeric Truncation Error", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Truncation errors occur when a primitive is cast to a primitive of a smaller size and data is lost in the conversion.", "extended_description": "When a primitive is cast to a smaller primitive, the high order bits of the large value are lost in the conversion, potentially resulting in an unexpected value that is not equal to the original value. This value may be required as an index into a buffer, a loop iterator, or simply necessary state data. In any case, the value cannot be trusted and the system will be in an undefined state. While this method may be employed viably to isolate the low bits of a value, this usage is rare, and truncat...", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Memory"]}], "mitigations": [{"description": "Ensure that no casts, implicit or explicit, take place that move from a larger size primitive or a smaller size primitive.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2020-17087", "description": "Chain: integer truncation (CWE-197) causes small buffer allocation (CWE-131) leading to out-of-bounds write (CWE-787) in kernel pool, as exploited in ..."}, {"cve": "CVE-2009-0231", "description": "Integer truncation of length value leads to heap-based buffer overflow."}, {"cve": "CVE-2008-3282", "description": "Size of a particular type changes for 64-bit platforms, leading to an integer truncation in document processor causes incorrect index to be generated."}], "platforms": {"languages": ["C", "C++", "Java", "C#"]}}, "198": {"name": "Use of Incorrect Byte Ordering", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not account for byte ordering (e.g. big-endian and little-endian) when processing the input, causing an incorrect number or value to be used.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "detection_methods": [{"method": "Black Box", "description": "Because byte ordering bugs are usually very noticeable even with normal inputs, this bug is more likely to occur in rarely triggered error conditions, making them difficult to detect using black box m..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "20": {"name": "Improper Input Validation", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product receives input or data, but it does\n        not validate or incorrectly validates that the input has the\n        properties that are required to process the data safely and\n        correctly.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)"]}, {"scope": ["Confidentiality"], "impact": ["Read Memory", "Read Files or Directories"]}, {"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Modify Memory", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Consider using language-theoretic security (LangSec) techniques that characterize inputs using a formal language and build \"recognizers\" for that language.  This effectively requires parsing to be a distinct layer that effectively enforces a boundary between raw input and internal data representatio...", "phase": ["Architecture and Design"]}, {"description": "Use an input validation framework such as Struts or the OWASP ESAPI Validation API. Note that using a framework does not automatically address all input validation problems; be mindful of weaknesses that could arise from misusing the framework itself (CWE-1173).", "phase": ["Architecture and Design"]}, {"description": "Understand all the potential areas where untrusted inputs can enter the product, including but not limited to: parameters or arguments, cookies, anything read from the network, environment variables, reverse DNS lookups, query results, request headers, URL components, e-mail, files, filenames, datab...", "phase": ["Architecture and Design", "Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis"}, {"method": "Manual Static Analysis", "description": "When custom input validation is required, such as when enforcing business rules, manual analysis is necessary to ensure that the validation is properly implemented."}, {"method": "Fuzzing", "description": "Fuzzing techniques can be useful for detecting input validation errors. When unexpected inputs are provided to the software, the software should not crash or otherwise become unstable, and it should g..."}], "observed_examples": [{"cve": "CVE-2024-37032", "description": "Large language model (LLM) management tool does not\n               validate the format of a digest value (CWE-1287) from a\n               private, unt..."}, {"cve": "CVE-2022-45918", "description": "Chain: a learning management tool debugger uses external input to locate previous session logs (CWE-73) and does not properly validate the given path ..."}, {"cve": "CVE-2021-30860", "description": "Chain: improper input validation (CWE-20) leads to integer overflow (CWE-190) in mobile OS, as exploited in the wild per CISA KEV."}, {"cve": "CVE-2021-30663", "description": "Chain: improper input validation (CWE-20) leads to integer overflow (CWE-190) in mobile OS, as exploited in the wild per CISA KEV."}, {"cve": "CVE-2021-22205", "description": "Chain: backslash followed by a newline can bypass a validation step (CWE-20), leading to eval injection (CWE-95), as exploited in the wild per CISA KE..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "200": {"name": "Exposure of Sensitive Information to an Unauthorized Actor", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "detection_methods": [{"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Dynamic Analysis with Automated Results Interpretation"}, {"method": "Dynamic Analysis with Manual Results Interpretation"}], "observed_examples": [{"cve": "CVE-2022-31162", "description": "Rust library leaks Oauth client details in application debug logs"}, {"cve": "CVE-2021-25476", "description": "Digital Rights Management (DRM) capability for mobile platform leaks pointer information, simplifying ASLR bypass"}, {"cve": "CVE-2001-1483", "description": "Enumeration of valid usernames based on inconsistent responses"}, {"cve": "CVE-2001-1528", "description": "Account number enumeration via inconsistent responses."}, {"cve": "CVE-2004-2150", "description": "User enumeration via discrepancies in error messages."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based", "Mobile"]}}, "201": {"name": "Insertion of Sensitive Information Into Sent Data", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Files or Directories", "Read Memory", "Read Application Data"]}], "mitigations": [{"description": "Specify which data in the software should be regarded as sensitive. Consider which types of users should have access to which types of data.", "phase": ["Requirements"]}, {"description": "Ensure that any possibly sensitive data specified in the requirements is verified with designers to ensure that it is either a calculated risk or mitigated elsewhere. Any information that is not necessary to the functionality should be removed in order to lower both the overhead and the possibility ...", "phase": ["Implementation"]}, {"description": "Setup default error messages so that unexpected errors do not disclose sensitive information.", "phase": ["System Configuration"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-0708", "description": "Collaboration platform does not clear team emails in a response, allowing leak of email addresses"}], "platforms": {"languages": ["Not Language-Specific"]}}, "202": {"name": "Exposure of Sensitive Information Through Data Queries", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "When trying to keep information confidential, an attacker can often infer some of the information by using statistics.", "extended_description": "In situations where data should not be tied to individual users, but a large number of users should be able to make queries that \"scrub\" the identity of users, it may be possible to get information about a user -- e.g., by specifying search terms that are known to be unique to that user.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Files or Directories", "Read Application Data"]}], "mitigations": [{"description": "This is a complex topic. See the [REF-1492] for a good discussion of best practices.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2022-41935", "description": "Wiki product allows an adversary to discover filenames via a series of queries starting with one letter and then iteratively extending the match."}], "platforms": {"languages": ["Not Language-Specific"]}}, "203": {"name": "Observable Discrepancy", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.", "extended_description": "Discrepancies can take many forms, and variations may be detectable in timing, control flow, communications such as replies or requests, or general behavior. These discrepancies can reveal information about the product's operation or internal state to an unauthorized actor. In some cases, discrepancies can be used by attackers to form a side channel.", "consequences": [{"scope": ["Confidentiality", "Access Control"], "impact": ["Read Application Data", "Bypass Protection Mechanism"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "observed_examples": [{"cve": "CVE-2020-8695", "description": "Observable discrepancy in the RAPL interface for some Intel processors allows information disclosure."}, {"cve": "CVE-2019-14353", "description": "Crypto hardware wallet's power consumption relates to total number of pixels illuminated, creating a side channel in the USB connection that allows at..."}, {"cve": "CVE-2019-10071", "description": "Java-oriented framework compares HMAC signatures  using  String.equals() instead of a constant-time algorithm, causing timing discrepancies"}, {"cve": "CVE-2002-2094", "description": "This, and others, use \"..\" attacks and monitor error responses, so there is overlap with directory traversal."}, {"cve": "CVE-2001-1483", "description": "Enumeration of valid usernames based on inconsistent responses"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "204": {"name": "Observable Response Discrepancy", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.", "consequences": [{"scope": ["Confidentiality", "Access Control"], "impact": ["Read Application Data", "Bypass Protection Mechanism"]}], "observed_examples": [{"cve": "CVE-2002-2094", "description": "This, and others, use \"..\" attacks and monitor error responses, so there is overlap with directory traversal."}, {"cve": "CVE-2001-1483", "description": "Enumeration of valid usernames based on inconsistent responses"}, {"cve": "CVE-2001-1528", "description": "Account number enumeration via inconsistent responses."}, {"cve": "CVE-2004-2150", "description": "User enumeration via discrepancies in error messages."}, {"cve": "CVE-2005-1650", "description": "User enumeration via discrepancies in error messages."}], "platforms": {"languages": ["Not Language-Specific"]}}, "205": {"name": "Observable Behavioral Discrepancy", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product's behaviors indicate important differences that may be observed by unauthorized actors in a way that reveals (1) its internal state or decision process, or (2) differences from other products with equivalent functionality.", "extended_description": "Ideally, a product should provide as little information about its internal operations as possible.  Otherwise, attackers could use knowledge of these internal operations to simplify or optimize their attack.  In some cases, behavioral discrepancies can be used by attackers to form a side channel.", "consequences": [{"scope": ["Confidentiality", "Access Control"], "impact": ["Read Application Data", "Bypass Protection Mechanism"]}], "observed_examples": [{"cve": "CVE-2002-0208", "description": "Product modifies TCP/IP stack and ICMP error messages in unusual ways that show the product is in use."}, {"cve": "CVE-2004-2252", "description": "Behavioral infoleak by responding to SYN-FIN packets."}], "platforms": {"languages": ["Not Language-Specific"]}}, "206": {"name": "Observable Internal Behavioral Discrepancy", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product performs multiple behaviors that are combined to produce a single result, but the individual behaviors are observable separately in a way that allows attackers to reveal internal state or internal decision points.", "extended_description": "Ideally, a product should provide as little information as possible to an attacker.  Any hints that the attacker may be making progress can then be used to simplify or optimize the attack.  For example, in a login procedure that requires a username and password, ultimately there is only one decision: success or failure.  However, internally, two separate actions are performed: determining if the username exists, and checking if the password is correct.  If the product behaves differently based o...", "consequences": [{"scope": ["Confidentiality", "Access Control"], "impact": ["Read Application Data", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Setup generic response pages for error conditions. The error page should not disclose information about the success or failure of a sensitive operation. For instance, the login page should not confirm that the login is correct and the password incorrect. The attacker who tries random account name ma..."}], "observed_examples": [{"cve": "CVE-2002-2031", "description": "File existence via infoleak monitoring whether \"onerror\" handler fires or not."}, {"cve": "CVE-2005-2025", "description": "Valid groupname enumeration via behavioral infoleak (sends response if valid, doesn't respond if not)."}, {"cve": "CVE-2001-1497", "description": "Behavioral infoleak in GUI allows attackers to distinguish between alphanumeric and non-alphanumeric characters in a password, thus reducing the searc..."}, {"cve": "CVE-2003-0190", "description": "Product immediately sends an error message when user does not exist instead of waiting until the password is provided, allowing username enumeration."}], "platforms": {"languages": ["Not Language-Specific"]}}, "207": {"name": "Observable Behavioral Discrepancy With Equivalent Products", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product operates in an environment in which its existence or specific identity should not be known, but it behaves differently than other products with equivalent functionality, in a way that is observable to an attacker.", "extended_description": "For many kinds of products, multiple products may be available that perform the same functionality, such as a web server, network interface, or intrusion detection system.  Attackers often perform \"fingerprinting,\" which uses discrepancies in order to identify which specific product is in use.  Once the specific product has been identified, the attacks can be made more customized and efficient.  Often, an organization might intentionally allow the specific product to be identifiable.  However, i...", "consequences": [{"scope": ["Confidentiality", "Access Control"], "impact": ["Read Application Data", "Bypass Protection Mechanism"]}], "observed_examples": [{"cve": "CVE-2002-0208", "description": "Product modifies TCP/IP stack and ICMP error messages in unusual ways that show the product is in use."}, {"cve": "CVE-2004-2252", "description": "Behavioral infoleak by responding to SYN-FIN packets."}, {"cve": "CVE-2000-1142", "description": "Honeypot generates an error with a \"pwd\" command in a particular directory, allowing attacker to know they are in a honeypot system."}], "platforms": {"languages": ["Not Language-Specific"]}}, "208": {"name": "Observable Timing Discrepancy", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.", "extended_description": "In security-relevant contexts, even small variations in timing can be exploited by attackers to indirectly infer certain details about the product's internal operations.  For example, in some cryptographic algorithms, attackers can use timing differences to infer certain properties about a private key, making the key easier to guess.  Timing discrepancies effectively form a timing side channel.", "consequences": [{"scope": ["Confidentiality", "Access Control"], "impact": ["Read Application Data", "Bypass Protection Mechanism"]}], "observed_examples": [{"cve": "CVE-2019-10071", "description": "Java-oriented framework compares HMAC signatures  using  String.equals() instead of a constant-time algorithm, causing timing discrepancies"}, {"cve": "CVE-2019-10482", "description": "Smartphone OS uses comparison functions that are not in constant time, allowing side channels"}, {"cve": "CVE-2014-0984", "description": "Password-checking function in router terminates validation of a password entry when it encounters the first incorrect character, which allows remote a..."}, {"cve": "CVE-2003-0078", "description": "SSL implementation does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepan..."}, {"cve": "CVE-2000-1117", "description": "Virtual machine allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getS..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "209": {"name": "Generation of Error Message Containing Sensitive Information", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product generates an error message that includes sensitive information about its environment, users, or associated data.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Handle exceptions internally and do not display errors containing potentially sensitive information to a user.", "phase": ["Implementation"]}, {"description": "Use naming conventions and strong types to make it easier to spot when sensitive data is being used. When creating structures, objects, or other complex entities, separate the sensitive and non-sensitive data as much as possible.", "phase": ["Implementation"]}, {"description": "Debugging information should not make its way into a production release.", "phase": ["Implementation", "Build and Compilation"]}], "detection_methods": [{"method": "Manual Analysis", "description": "This weakness generally requires domain-specific interpretation using manual analysis. However, the number of potential error conditions may be too large to cover completely within limited time constr..."}, {"method": "Automated Analysis", "description": "Automated methods may be able to detect certain idioms automatically, such as exposed stack traces or pathnames, but violation of business rules or privacy requirements is not typically feasible."}, {"method": "Automated Dynamic Analysis"}], "observed_examples": [{"cve": "CVE-2008-2049", "description": "POP3 server reveals a password in an error message after multiple APOP commands are sent. Might be resultant from another weakness."}, {"cve": "CVE-2007-5172", "description": "Program reveals password in error message if attacker can trigger certain database errors."}, {"cve": "CVE-2008-4638", "description": "Composite: application running with high privileges (CWE-250) allows user to specify a restricted file to process, which generates a parsing error tha..."}, {"cve": "CVE-2008-1579", "description": "Existence of user names can be determined by requesting a nonexistent blog and reading the error message."}, {"cve": "CVE-2007-1409", "description": "Direct request to library file in web application triggers pathname leak in error message."}], "platforms": {"languages": ["PHP", "Java", "Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "210": {"name": "Self-generated Error Message Containing Sensitive Information", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product identifies an error condition and creates its own diagnostic or error messages that contain sensitive information.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Debugging information should not make its way into a production release.", "phase": ["Implementation", "Build and Compilation"]}, {"description": "Debugging information should not make its way into a production release.", "phase": ["Implementation", "Build and Compilation"]}], "observed_examples": [{"cve": "CVE-2005-1745", "description": "Infoleak of sensitive information in error message (physical access required)."}], "platforms": {"languages": ["Not Language-Specific"]}}, "211": {"name": "Externally-Generated Error Message Containing Sensitive Information", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product performs an operation that triggers an external diagnostic or error message that is not directly generated or controlled by the product, such as an error generated by the programming language interpreter that a software application uses. The error can contain sensitive system information.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Configure the application's environment in a way that prevents errors from being generated. For example, in PHP, disable display_errors.", "phase": ["System Configuration"]}, {"description": "Debugging information should not make its way into a production release.", "phase": ["Implementation", "Build and Compilation"]}, {"description": "Debugging information should not make its way into a production release.", "phase": ["Implementation", "Build and Compilation"]}], "observed_examples": [{"cve": "CVE-2004-1581", "description": "chain: product does not protect against direct request of an include file, leading to resultant path disclosure when the include file does not success..."}, {"cve": "CVE-2004-1579", "description": "Single \"'\" inserted into SQL query leads to invalid SQL query execution, triggering full path disclosure. Possibly resultant from more general SQL inj..."}, {"cve": "CVE-2005-0459", "description": "chain: product does not protect against direct request of a library file, leading to resultant path disclosure when the file does not successfully exe..."}, {"cve": "CVE-2005-0443", "description": "invalid parameter triggers a failure to find an include file, leading to infoleak in error message."}, {"cve": "CVE-2005-0433", "description": "Various invalid requests lead to information leak in verbose error messages describing the failure to instantiate a class, open a configuration file, ..."}], "platforms": {"languages": ["PHP", "Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "212": {"name": "Improper Removal of Sensitive Information Before Storage or Transfer", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Files or Directories", "Read Application Data"]}], "mitigations": [{"description": "Clearly specify which information should be regarded as private or sensitive, and require that the product offers functionality that allows the user to cleanse the sensitive information from the resource before it is published or exported to other parties.", "phase": ["Requirements"]}, {"description": "Use naming conventions and strong types to make it easier to spot when sensitive data is being used. When creating structures, objects, or other complex entities, separate the sensitive and non-sensitive data as much as possible.", "phase": ["Implementation"]}, {"description": "Avoid errors related to improper resource shutdown or release (CWE-404), which may leave the sensitive data within the resource if it is in an incomplete state.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Tools are available to analyze documents\n\t\t\t (such as PDF, Word, etc.) to look for private information\n\t\t\t such as names, addresses, etc."}], "observed_examples": [{"cve": "CVE-2020-26220", "description": "Customer relationship management (CRM) product does not strip Exif data from images"}, {"cve": "CVE-2019-3733", "description": "Cryptography library does not clear heap memory before release"}, {"cve": "CVE-2005-0406", "description": "Some image editors modify a JPEG image, but the original EXIF thumbnail image is left intact within the JPEG. (Also an interaction error)."}, {"cve": "CVE-2002-0704", "description": "NAT feature in firewall leaks internal IP addresses in ICMP error messages."}], "platforms": {"languages": ["Not Language-Specific"]}}, "213": {"name": "Exposure of Sensitive Information Due to Incompatible Policies", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product's intended functionality exposes information to certain actors in accordance with the developer's security policy, but this information is regarded as sensitive according to the intended security policies of other stakeholders such as the product's administrator, users, or others whose information is being processed.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "observed_examples": [{"cve": "CVE-2002-1725", "description": "Script calls phpinfo()"}, {"cve": "CVE-2004-0033", "description": "Script calls phpinfo()"}, {"cve": "CVE-2003-1181", "description": "Script calls phpinfo()"}, {"cve": "CVE-2004-1422", "description": "Script calls phpinfo()"}, {"cve": "CVE-2004-1590", "description": "Script calls phpinfo()"}], "platforms": {"languages": ["Not Language-Specific"]}}, "214": {"name": "Invocation of Process Using Visible Sensitive Information", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A process is invoked with sensitive command-line arguments, environment variables, or other elements that can be seen by other processes on the operating system.", "extended_description": "Many operating systems allow a user to list information about processes that are owned by other users. Other users could see information such as command line arguments or environment variable settings. When this data contains sensitive information such as credentials, it might allow other users to launch an attack against the product or related resources.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "observed_examples": [{"cve": "CVE-2005-1387", "description": "password passed on command line"}, {"cve": "CVE-2005-2291", "description": "password passed on command line"}, {"cve": "CVE-2001-1565", "description": "username/password on command line allows local users to view via \"ps\" or other process listing programs"}, {"cve": "CVE-2004-1948", "description": "Username/password on command line allows local users to view via \"ps\" or other process listing programs."}, {"cve": "CVE-1999-1270", "description": "PGP passphrase provided as command line argument."}], "platforms": {"languages": ["Not Language-Specific"]}}, "215": {"name": "Insertion of Sensitive Information Into Debugging Code", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.", "extended_description": "When debugging, it may be necessary to report detailed information to the programmer.  However, if the debugging code is not disabled when the product is operating in a production environment, then this sensitive information may be exposed to attackers.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Do not leave debug statements that could be executed in the source code. Ensure that all debug information is eradicated before releasing the software.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2004-2268", "description": "Password exposed in debug information."}, {"cve": "CVE-2002-0918", "description": "CGI script includes sensitive information in debug messages when an error is triggered."}, {"cve": "CVE-2003-1078", "description": "FTP client with debug option enabled shows password to the screen."}], "platforms": {"languages": ["Not Language-Specific"]}}, "216": {"name": "DEPRECATED: Containment Errors (Container Errors)", "abstraction": "Class", "mapping": "PROHIBITED", "structure": "Simple", "description": "This entry has been deprecated, as it was not effective as a weakness and was structured more like a category. In addition, the name is inappropriate, since the \"container\" term is widely understood by developers in different ways than originally intended by PLOVER, the original source for this entry."}, "217": {"name": "DEPRECATED: Failure to Protect Stored Data from Modification", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "This entry has been deprecated because it incorporated and confused multiple weaknesses. The issues formerly covered in this entry can be found at CWE-766 and CWE-767."}, "218": {"name": "DEPRECATED: Failure to provide confidentiality for stored data", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "This weakness has been deprecated because it was a duplicate of CWE-493. All content has been transferred to CWE-493."}, "219": {"name": "Storage of File with Sensitive Data Under Web Root", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores sensitive data under the web document root with insufficient access control, which might make it accessible to untrusted parties.", "extended_description": "Besides public-facing web pages and code, products may store sensitive data, code that is not directly invoked, or other files under the web document root of the web server.  If the server is not configured or otherwise used to prevent direct access to those files, then attackers may obtain this sensitive data.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Avoid storing information under the web root directory.", "phase": ["Implementation", "System Configuration"]}, {"description": "Access control permissions should be set to prevent reading/writing of sensitive files inside/outside of the web directory.", "phase": ["System Configuration"]}], "observed_examples": [{"cve": "CVE-2005-1835", "description": "Data file under web root."}, {"cve": "CVE-2005-2217", "description": "Data file under web root."}, {"cve": "CVE-2002-1449", "description": "Username/password in data file under web root."}, {"cve": "CVE-2002-0943", "description": "Database file under web root."}, {"cve": "CVE-2005-1645", "description": "database file under web root."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "22": {"name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')", "abstraction": "Base", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Integrity"], "impact": ["Modify Files or Directories"]}, {"scope": ["Confidentiality"], "impact": ["Read Files or Directories"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-s...", "phase": ["Architecture and Design"]}, {"description": "Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482].", "phase": ["Architecture and Design"]}, {"description": "Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide d...", "phase": ["Operation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated techniques can find areas where path traversal weaknesses exist. However, tuning or customization may be required to remove or de-prioritize path-traversal problems that are only exploitable..."}, {"method": "Manual Static Analysis", "description": "Manual white box techniques may be able to provide sufficient code coverage and reduction of false positives if all file access operations can be assessed within limited time constraints."}, {"method": "Automated Static Analysis - Binary or Bytecode"}], "observed_examples": [{"cve": "CVE-2024-37032", "description": "Large language model (LLM) management tool does not\n               validate the format of a digest value (CWE-1287) from a\n               private, unt..."}, {"cve": "CVE-2024-4315", "description": "Chain: API for text generation using Large Language Models (LLMs) does\n\t\t\t   not include the \"\\\" Windows folder separator in its denylist (CWE-184)\n\t\t..."}, {"cve": "CVE-2024-0520", "description": "Product for managing datasets for AI model training and evaluation allows both relative (CWE-23) and absolute (CWE-36) path traversal to overwrite fil..."}, {"cve": "CVE-2022-45918", "description": "Chain: a learning management tool debugger uses external input to locate previous session logs (CWE-73) and does not properly validate the given path ..."}, {"cve": "CVE-2019-20916", "description": "Python package manager does not correctly restrict the filename specified in a Content-Disposition header, allowing arbitrary file read using path tra..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["AI/ML"]}}, "220": {"name": "Storage of File With Sensitive Data Under FTP Root", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores sensitive data under the FTP server root with insufficient access control, which might make it accessible to untrusted parties.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Avoid storing information under the FTP root directory.", "phase": ["Implementation", "System Configuration"]}, {"description": "Access control permissions should be set to prevent reading/writing of sensitive files inside/outside of the FTP directory.", "phase": ["System Configuration"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "221": {"name": "Information Loss or Omission", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not record, or improperly records, security-relevant information that leads to an incorrect decision or hampers later analysis.", "consequences": [{"scope": ["Non-Repudiation"], "impact": ["Hide Activities"]}], "observed_examples": [{"cve": "CVE-2004-2227", "description": "Web browser's filename selection dialog only shows the beginning portion of long filenames, which can trick users into launching executables with dang..."}, {"cve": "CVE-2003-0412", "description": "application server does not log complete URI of a long request (truncation)."}, {"cve": "CVE-1999-1029", "description": "Login attempts are not recorded if the user disconnects before the maximum number of tries."}, {"cve": "CVE-2002-0725", "description": "Attacker performs malicious actions on a hard link to a file, obscuring the real target file."}, {"cve": "CVE-1999-1055", "description": "Product does not warn user when document contains certain dangerous functions or macros."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "222": {"name": "Truncation of Security-relevant Information", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product truncates the display, recording, or processing of security-relevant information in a way that can obscure the source or nature of an attack.", "consequences": [{"scope": ["Non-Repudiation"], "impact": ["Hide Activities"]}], "observed_examples": [{"cve": "CVE-2005-0585", "description": "Web browser truncates long sub-domains or paths, facilitating phishing."}, {"cve": "CVE-2004-2032", "description": "Bypass URL filter via a long URL with a large number of trailing hex-encoded space characters."}, {"cve": "CVE-2003-0412", "description": "application server does not log complete URI of a long request (truncation)."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "223": {"name": "Omission of Security-relevant Information", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not record or display information that would be important for identifying the source or nature of an attack, or determining if an action is safe.", "consequences": [{"scope": ["Non-Repudiation"], "impact": ["Hide Activities"]}], "observed_examples": [{"cve": "CVE-1999-1029", "description": "Login attempts are not recorded if the user disconnects before the maximum number of tries."}, {"cve": "CVE-2002-1839", "description": "Sender's IP address not recorded in outgoing e-mail."}, {"cve": "CVE-2000-0542", "description": "Failed authentication attempts are not recorded if later attempt succeeds."}], "platforms": {"languages": ["Not Language-Specific"]}}, "224": {"name": "Obscured Security-relevant Information by Alternate Name", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product records security-relevant information according to an alternate name of the affected entity, instead of the canonical name.", "consequences": [{"scope": ["Non-Repudiation", "Access Control"], "impact": ["Hide Activities", "Gain Privileges or Assume Identity"]}], "observed_examples": [{"cve": "CVE-2002-0725", "description": "Attacker performs malicious actions on a hard link to a file, obscuring the real target file."}], "platforms": {"languages": ["Not Language-Specific"]}}, "225": {"name": "DEPRECATED: General Information Management Problems", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "This weakness can be found at CWE-199."}, "226": {"name": "Sensitive Information in Resource Not Removed Before Reuse", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product releases a resource such as memory or a file so that it can be made available for reuse, but it does not clear or \"zeroize\" the information contained in the resource before the product performs a critical state transition or makes the resource available for reuse by other entities.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "During critical state transitions, information not needed in the next state should be removed or overwritten with fixed patterns (such as all 0's) or random data, before the transition to the next state.", "phase": ["Architecture and Design", "Implementation"]}, {"description": "When releasing, de-allocating, or deleting a resource, overwrite its data and relevant metadata with fixed patterns or random data. Be cautious about complex resource types whose underlying representation might be non-contiguous or change at a low level, such as how a file might be split into differ...", "phase": ["Architecture and Design", "Implementation"]}], "detection_methods": [{"method": "Manual Analysis", "description": "Write a known pattern into each sensitive location. Trigger the release of the resource or cause the desired state transition to occur. Read data back from the sensitive locations. If the reads are su..."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2019-3733", "description": "Cryptography library does not clear heap memory before release"}, {"cve": "CVE-2003-0001", "description": "Ethernet NIC drivers do not pad frames with null bytes, leading to infoleak from malformed packets."}, {"cve": "CVE-2003-0291", "description": "router does not clear information from DHCP packets that have been previously used"}, {"cve": "CVE-2005-1406", "description": "Products do not fully clear memory buffers when less data is stored into the buffer than previous."}, {"cve": "CVE-2005-1858", "description": "Products do not fully clear memory buffers when less data is stored into the buffer than previous."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "228": {"name": "Improper Handling of Syntactically Invalid Structure", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not handle or incorrectly handles input that is not syntactically well-formed with respect to the associated specification.", "consequences": [{"scope": ["Integrity", "Availability"], "impact": ["Unexpected State", "DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2004-0270", "description": "Anti-virus product has assert error when line length is non-numeric."}], "platforms": {"languages": ["Not Language-Specific"]}}, "229": {"name": "Improper Handling of Values", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly handle when the expected number of values for parameters, fields, or arguments is not provided in input, or if those values are undefined.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "23": {"name": "Relative Path Traversal", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as \"..\" that can resolve to a location that is outside of that directory.", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Integrity"], "impact": ["Modify Files or Directories"]}, {"scope": ["Confidentiality"], "impact": ["Read Files or Directories"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide d...", "phase": ["Operation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2024-37032", "description": "Large language model (LLM) management tool does not\n               validate the format of a digest value (CWE-1287) from a\n               private, unt..."}, {"cve": "CVE-2024-0520", "description": "Product for managing datasets for AI model training and evaluation allows both relative (CWE-23) and absolute (CWE-36) path traversal to overwrite fil..."}, {"cve": "CVE-2022-45918", "description": "Chain: a learning management tool debugger uses external input to locate previous session logs (CWE-73) and does not properly validate the given path ..."}, {"cve": "CVE-2019-20916", "description": "Python package manager does not correctly restrict the filename specified in a Content-Disposition header, allowing arbitrary file read using path tra..."}, {"cve": "CVE-2022-24877", "description": "directory traversal in Go-based Kubernetes operator app allows accessing data from the controller's pod file system via ../ sequences in a yaml file"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based", "AI/ML"]}}, "230": {"name": "Improper Handling of Missing Values", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not handle or incorrectly handles when a parameter, field, or argument name is specified, but the associated value is missing, i.e. it is empty, blank, or null.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "observed_examples": [{"cve": "CVE-2002-0422", "description": "Blank Host header triggers resultant infoleak."}, {"cve": "CVE-2000-1006", "description": "Blank \"charset\" attribute in MIME header triggers crash."}, {"cve": "CVE-2004-1504", "description": "Blank parameter causes external error infoleak."}, {"cve": "CVE-2005-2053", "description": "Blank parameter causes external error infoleak."}], "platforms": {"languages": ["Not Language-Specific"]}}, "231": {"name": "Improper Handling of Extra Values", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not handle or incorrectly handles when more values are provided than expected.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "232": {"name": "Improper Handling of Undefined Values", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not handle or incorrectly handles when a value is not defined or supported for the associated parameter, field, or argument name.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "observed_examples": [{"cve": "CVE-2000-1003", "description": "Client crash when server returns unknown driver type."}], "platforms": {"languages": ["Not Language-Specific"]}}, "233": {"name": "Improper Handling of Parameters", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly handle when the expected number of parameters, fields, or arguments is not provided in input, or if those parameters are undefined.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "234": {"name": "Failure to Handle Missing Parameter", "abstraction": "Variant", "mapping": "DISCOURAGED", "structure": "Simple", "description": "If too few arguments are sent to a function, the function will still pop the expected number of arguments from the stack. Potentially, a variable number of arguments could be exhausted in a function as well.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability", "Access Control"], "impact": ["Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "This issue can be simply combated with the use of proper build process.", "phase": ["Build and Compilation"]}, {"description": "Forward declare all functions. This is the recommended solution. Properly forward declaration of all used functions will result in a compiler error if too few arguments are sent to a function.", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2004-0276", "description": "Server earlier allows remote attackers to cause a denial of service (crash) via an HTTP request with a sequence of \"%\" characters and a missing Host f..."}, {"cve": "CVE-2002-1488", "description": "Chat client allows remote malicious IRC servers to cause a denial of service (crash) via a PART message with (1) a missing channel or (2) a channel th..."}, {"cve": "CVE-2002-1169", "description": "Proxy allows remote attackers to cause a denial of service (crash) via an HTTP request to helpout.exe with a missing HTTP version numbers."}, {"cve": "CVE-2000-0521", "description": "Web server allows disclosure of CGI source code via an HTTP request without the version number."}, {"cve": "CVE-2001-0590", "description": "Application server allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HT..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "235": {"name": "Improper Handling of Extra Parameters", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not handle or incorrectly handles when the number of parameters, fields, or arguments with the same name exceeds the expected amount.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "observed_examples": [{"cve": "CVE-2003-1014", "description": "MIE. multiple gateway/security products allow restriction bypass using multiple MIME fields with the same name, which are interpreted differently by c..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "236": {"name": "Improper Handling of Undefined Parameters", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not handle or incorrectly handles when a particular parameter, field, or argument name is not defined or supported by the product.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "observed_examples": [{"cve": "CVE-2002-1488", "description": "Crash in IRC client via PART message from a channel the user is not in."}, {"cve": "CVE-2001-0650", "description": "Router crash or bad route modification using BGP updates with invalid transitive attribute."}], "platforms": {"languages": ["Not Language-Specific"]}}, "237": {"name": "Improper Handling of Structural Elements", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not handle or incorrectly handles inputs that are related to complex structures.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "238": {"name": "Improper Handling of Incomplete Structural Elements", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not handle or incorrectly handles when a particular structural element is not completely specified.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "239": {"name": "Failure to Handle Incomplete Element", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly handle when a particular element is not completely specified.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Varies by Context", "Unexpected State"]}], "observed_examples": [{"cve": "CVE-2002-1532", "description": "HTTP GET without \\r\\n\\r\\n CRLF sequences causes product to wait indefinitely and prevents other users from accessing it."}, {"cve": "CVE-2003-0195", "description": "Partial request is not timed out."}, {"cve": "CVE-2005-2526", "description": "MFV. CPU exhaustion in printer via partial printing request then early termination of connection."}, {"cve": "CVE-2002-1906", "description": "CPU consumption by sending incomplete HTTP requests and leaving the connections open."}], "platforms": {"languages": ["Not Language-Specific"]}}, "24": {"name": "Path Traversal: '../filedir'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize \"../\" sequences that can resolve to a location that is outside of that directory.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-45918", "description": "Chain: a learning management tool debugger uses external input to locate previous session logs (CWE-73) and does not properly validate the given path ..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "240": {"name": "Improper Handling of Inconsistent Structural Elements", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not handle or incorrectly handles when two or more structural elements should be consistent, but are not.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Varies by Context", "Unexpected State"]}], "observed_examples": [{"cve": "CVE-2014-0160", "description": "Chain: \"Heartbleed\" bug receives an inconsistent length parameter (CWE-130) enabling an out-of-bounds read (CWE-126), returning memory that could incl..."}, {"cve": "CVE-2009-2299", "description": "Web application firewall consumes excessive memory when an HTTP request contains a large Content-Length value but no POST data."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "241": {"name": "Improper Handling of Unexpected Data Type", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not handle or incorrectly handles when a particular element is not the expected type, e.g. it expects a digit (0-9) but is provided with a letter (A-Z).", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Varies by Context", "Unexpected State"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-1999-1156", "description": "FTP server crash via PORT command with non-numeric character."}, {"cve": "CVE-2004-0270", "description": "Anti-virus product has assert error when line length is non-numeric."}], "platforms": {"languages": ["Not Language-Specific"]}}, "242": {"name": "Use of Inherently Dangerous Function", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product calls a function that can never be guaranteed to work safely.", "extended_description": "Certain functions behave in dangerous ways regardless of how they are used. Functions in this category were often implemented without taking security concerns into account. The gets() function is unsafe because it does not perform bounds checking on the size of its input. An attacker can easily send arbitrarily-sized input to gets() and overflow the destination buffer. Similarly, the >> operator is unsafe to use when reading into a statically-allocated character array because it does not perform...", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Ban the use of dangerous functions. Use their safe equivalent.", "phase": ["Implementation", "Requirements"]}, {"description": "Use grep or static analysis tools to spot usage of dangerous functions.", "phase": ["Testing"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2007-4004", "description": "FTP client uses inherently insecure gets() function and is setuid root on some systems, allowing buffer overflow"}], "platforms": {"languages": ["C", "C++"]}}, "243": {"name": "Creation of chroot Jail Without Changing Working Directory", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses the chroot() system call to create a jail, but does not change the working directory afterward. This does not prevent access to files outside of the jail.", "extended_description": "Improper use of chroot() may allow attackers to escape from the chroot jail. The chroot() function call does not change the process's current working directory, so relative paths may still refer to file system resources outside of the chroot jail after chroot() has been called.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Files or Directories"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C", "C++"]}}, "244": {"name": "Improper Clearing of Heap Memory Before Release ('Heap Inspection')", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory.", "extended_description": "When sensitive data such as a password or an encryption key is not removed from memory, it could be exposed to an attacker using a \"heap inspection\" attack that reads the sensitive data using memory dumps or other methods. The realloc() function is commonly used to increase the size of a block of allocated memory. This operation often requires copying the contents of the old memory block into a new and larger block. This operation leaves the contents of the original block intact but inaccessible...", "consequences": [{"scope": ["Confidentiality", "Other"], "impact": ["Read Memory", "Other"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2019-3733", "description": "Cryptography library does not clear heap memory before release"}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "245": {"name": "J2EE Bad Practices: Direct Management of Connections", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The J2EE application directly manages connections, instead of using the container's connection management facilities.", "extended_description": "The J2EE standard forbids the direct management of connections. It requires that applications use the container's resource management facilities to obtain connections to resources. Every major web application container provides pooled database connection management as part of its resource management framework. Duplicating this functionality in an application is difficult and error prone, which is part of the reason it is forbidden under the J2EE standard.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"], "technologies": ["Web Based", "Web Server"]}}, "246": {"name": "J2EE Bad Practices: Direct Use of Sockets", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The J2EE application directly uses sockets instead of using framework method calls.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "mitigations": [{"description": "Use framework method calls instead of using sockets directly.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "247": {"name": "DEPRECATED: Reliance on DNS Lookups in a Security Decision", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "This entry has been deprecated because it was a duplicate of CWE-350. All content has been transferred to CWE-350."}, "248": {"name": "Uncaught Exception", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "An exception is thrown from a function, but it is not caught.", "extended_description": "When an exception is not caught, it may cause the program to crash or expose sensitive information.", "consequences": [{"scope": ["Availability", "Confidentiality"], "impact": ["DoS: Crash, Exit, or Restart", "Read Application Data"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2023-41151", "description": "SDK for OPC Unified Architecture (OPC UA) server has uncaught exception when a socket is blocked for writing but the server tries to send an error"}, {"cve": "CVE-2023-21087", "description": "Java code in a smartphone OS can encounter a \"boot loop\" due to an uncaught exception"}], "platforms": {"languages": ["C++", "Java", "C#"]}}, "249": {"name": "DEPRECATED: Often Misused: Path Manipulation", "abstraction": "Variant", "mapping": "PROHIBITED", "structure": "Simple", "description": "This entry has been deprecated because of name\n\tconfusion and an accidental combination of multiple\n\tweaknesses. Most of its content has been transferred to\n\tCWE-785."}, "25": {"name": "Path Traversal: '/../filedir'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize \"/../\" sequences that can resolve to a location that is outside of that directory.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-20775", "description": "A cloud management tool allows attackers to bypass the restricted shell using path traversal sequences like \"/../\" in the USER environment variable."}], "platforms": {"languages": ["Not Language-Specific"]}}, "250": {"name": "Execution with Unnecessary Privileges", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Gain Privileges or Assume Identity", "Execute Unauthorized Code or Commands", "Read Application Data", "DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the s...", "phase": ["Architecture and Design", "Operation"]}, {"description": "Identify the functionality that requires additional privileges, such as access to privileged operating system resources. Wrap and centralize this functionality if possible, and isolate the privileged code as much as possible from other code [REF-76]. Raise privileges as late as possible, and drop th...", "phase": ["Architecture and Design"]}, {"description": "Identify the functionality that requires additional privileges, such as access to privileged operating system resources. Wrap and centralize this functionality if possible, and isolate the privileged code as much as possible from other code [REF-76]. Raise privileges as late as possible, and drop th...", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Manual Analysis", "description": "This weakness can be detected using tools and techniques that require manual (human) analysis, such as penetration testing, threat modeling, and interactive tools that allow the tester to record and m..."}, {"method": "Black Box"}, {"method": "Automated Static Analysis - Binary or Bytecode"}], "observed_examples": [{"cve": "CVE-2007-4217", "description": "FTP client program on a certain OS runs with setuid privileges and has a buffer overflow. Most clients do not need extra privileges, so an overflow is..."}, {"cve": "CVE-2008-1877", "description": "Program runs with privileges and calls another program with the same privileges, which allows read of arbitrary files."}, {"cve": "CVE-2007-5159", "description": "OS incorrectly installs a program with setuid privileges, allowing users to gain privileges."}, {"cve": "CVE-2008-4638", "description": "Composite: application running with high privileges (CWE-250) allows user to specify a restricted file to process, which generates a parsing error tha..."}, {"cve": "CVE-2008-0162", "description": "Program does not drop privileges before calling another program, allowing code execution."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Mobile"]}}, "252": {"name": "Unchecked Return Value", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions.", "extended_description": "Two common programmer assumptions are \"this function call can never fail\" and \"it doesn't matter if this function call fails\". If an attacker can force the function to fail or otherwise return a value that is not expected, then the subsequent program logic could lead to a vulnerability, because the product is not in a state that the programmer assumes. For example, if the program calls a function to drop privileges but does not check the return code to ensure that privileges were successfully dr...", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Availability", "Integrity"], "impact": ["Unexpected State", "DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Check the results of all functions that return a value and verify that the value is expected.", "phase": ["Implementation"]}, {"description": "For any pointers that could have been modified or provided from a function that can return NULL, check the pointer for NULL before use. When working with a multithreaded or otherwise asynchronous environment, ensure that proper locking APIs are used to lock before the check, and unlock when it has f...", "phase": ["Implementation"]}, {"description": "Ensure that you account for all possible return values from the function.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2020-17533", "description": "Chain: unchecked return value (CWE-252) of some functions for policy enforcement leads to authorization bypass (CWE-862)"}, {"cve": "CVE-2020-6078", "description": "Chain: The return value of a function returning a pointer is not checked for success (CWE-252) resulting in the later use of an uninitialized variable..."}, {"cve": "CVE-2019-15900", "description": "Chain: sscanf() call is used to check if a username and group exists, but the return value of sscanf() call is not checked (CWE-252), causing an unini..."}, {"cve": "CVE-2007-3798", "description": "Unchecked return value leads to resultant integer overflow and code execution."}, {"cve": "CVE-2006-4447", "description": "Program does not check return value when invoking functions to drop privileges, which could leave users with higher privileges than expected by forcin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "253": {"name": "Incorrect Check of Function Return Value", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product incorrectly checks a return value from a function, which prevents it from detecting errors or exceptional conditions.", "extended_description": "Important and common functions will return some value about the success of its actions. This will alert the program whether or not to handle any errors caused by that function.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Availability", "Integrity"], "impact": ["Unexpected State", "DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Use a language or compiler that uses exceptions and requires the catching of those exceptions.", "phase": ["Architecture and Design"]}, {"description": "Properly check all functions which return a value.", "phase": ["Implementation"]}, {"description": "When designing any function make sure you return a value or throw an exception in case of an error.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2023-49286", "description": "Chain: function in web caching proxy does not correctly check a return value (CWE-253) leading to a reachable assertion (CWE-617)"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "256": {"name": "Plaintext Storage of a Password", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores a password in plaintext within resources such as memory or files.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Avoid storing passwords in easily accessible locations.", "phase": ["Architecture and Design"]}, {"description": "Consider storing cryptographic hashes of passwords as an alternative to storing in plaintext.", "phase": ["Architecture and Design"]}, {"description": "A programmer might attempt to remedy the password management problem by obscuring the password with an encoding function, such as base 64 encoding, but this effort does not adequately protect the password because the encoding can be detected and decoded easily."}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-30275", "description": "Remote Terminal Unit (RTU) uses a driver that relies on a password stored in plaintext."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["ICS/OT"]}}, "257": {"name": "Storing Passwords in a Recoverable Format", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The storage of passwords in a recoverable format makes them subject to password reuse attacks by malicious users. In fact, it should be noted that recoverable encrypted passwords provide no significant benefit over plaintext passwords since they are subject not only to reuse by malicious attackers but also by malicious insiders. If a system administrator can recover a password directly, or use a brute force search on the available information, the administrator can use the password on other accounts.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality", "Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Use strong, non-reversible encryption to protect stored passwords.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-30018", "description": "A messaging platform serializes all elements of User/Group objects, making private information available to adversaries"}], "platforms": {"languages": ["Not Language-Specific"]}}, "258": {"name": "Empty Password in Configuration File", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Using an empty string as a password is insecure.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Passwords should be at least eight characters long -- the longer the better. Avoid passwords that are in any way similar to other passwords you have. Avoid using words that may be found in a dictionary, names book, on a map, etc. Consider incorporating numbers and/or punctuation into your password. ...", "phase": ["System Configuration"]}], "observed_examples": [{"cve": "CVE-2022-26117", "description": "Network access control (NAC) product has a configuration file with an empty password"}], "platforms": {"languages": ["Not Language-Specific"]}}, "259": {"name": "Use of Hard-coded Password", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity", "Hide Activities", "Reduce Maintainability"]}], "mitigations": [{"description": "For outbound authentication: store passwords outside of the code in a strongly-protected, encrypted configuration file or database that is protected from access by all outsiders, including other local users on the same system. Properly protect the key (CWE-320). If you cannot use encryption to prote...", "phase": ["Architecture and Design"]}, {"description": "For inbound authentication: Rather than hard-code a default username and password for first time logins, utilize a \"first login\" mode that requires the user to enter a unique strong password.", "phase": ["Architecture and Design"]}, {"description": "Perform access control checks and limit which entities can access the feature that requires the hard-coded password. For example, a feature might only be enabled through the system console instead of through a network connection.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Manual Analysis", "description": "This weakness can be detected using tools and techniques that require manual (human) analysis, such as penetration testing, threat modeling, and interactive tools that allow the tester to record and m..."}, {"method": "Black Box"}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-29964", "description": "Distributed Control System (DCS) has hard-coded passwords for local shell access"}, {"cve": "CVE-2021-37555", "description": "Telnet service for IoT feeder for dogs and cats has hard-coded password [REF-1288]"}, {"cve": "CVE-2021-35033", "description": "Firmware for a WiFi router uses a hard-coded password for a BusyBox shell, allowing bypass of authentication through the UART port"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["ICS/OT"]}}, "26": {"name": "Path Traversal: '/dir/../filename'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize \"/dir/../filename\" sequences that can resolve to a location that is outside of that directory.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Server"]}}, "260": {"name": "Password in Configuration File", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores a password in a configuration file that might be accessible to actors who do not know the password.", "extended_description": "This can result in compromise of the system for which the password is used. An attacker could gain access to this file and learn the stored password or worse yet, change the password to one of their choosing.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Avoid storing passwords in easily accessible locations.", "phase": ["Architecture and Design"]}, {"description": "Consider storing cryptographic hashes of passwords as an alternative to storing in plaintext.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-38665", "description": "A continuous delivery pipeline management tool stores an unencypted password in a configuration file."}], "platforms": {"languages": ["Not Language-Specific"]}}, "261": {"name": "Weak Encoding for Password", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Obscuring a password with a trivial encoding does not protect the password.", "extended_description": "Password management issues occur when a password is stored in plaintext in an application's properties or configuration file. A programmer can attempt to remedy the password management problem by obscuring the password with an encoding function, such as base 64 encoding, but this effort does not adequately protect the password.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Passwords should be encrypted with keys that are at least 128 bits in length for adequate security."}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "262": {"name": "Not Using Password Aging", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not have a mechanism in place for managing password aging.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "As part of a product's design, require users to change their passwords regularly and avoid reusing previous passwords.", "phase": ["Architecture and Design"]}, {"description": "Developers might disable clipboard paste operations into password fields as a way to discourage users from pasting a password into a clipboard. However, this might encourage users to choose less-secure passwords that are easier to type, and it can reduce the usability of password managers [REF-1294]...", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "263": {"name": "Password Aging with Long Expiration", "abstraction": "Base", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product supports password aging, but the expiration period is too long.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Previously, \"password expiration\" was\n\t\t\t   widely advocated as a defense-in-depth approach to\n\t\t\t   minimize the risk of weak passwords, and it has become\n\t\t\t   a common practice.  Password expiration requires a\n\t\t\t   password to be changed within a fixed time window (such\n\t\t\t   as every 90 days). ...", "phase": ["Implementation"]}, {"description": "Ensure that password aging is limited so that there is a defined maximum age for passwords. Note that if the expiration window is too short, it can cause users to generate poor or predictable passwords.", "phase": ["Architecture and Design"]}, {"description": "Ensure that the user is notified several times leading up to the password expiration.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "266": {"name": "Incorrect Privilege Assignment", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.", "phase": ["Architecture and Design", "Operation"]}, {"description": "Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the s...", "phase": ["Architecture and Design", "Operation"]}], "observed_examples": [{"cve": "CVE-1999-1193", "description": "untrusted user placed in unix \"wheel\" group"}, {"cve": "CVE-2005-2741", "description": "Product allows users to grant themselves certain rights that can be used to escalate privileges."}, {"cve": "CVE-2005-2496", "description": "Product uses group ID of a user instead of the group, causing it to run with different privileges. This is resultant from some other unknown issue."}, {"cve": "CVE-2004-0274", "description": "Product mistakenly assigns a particular status to an entity, leading to increased privileges."}], "platforms": {"languages": ["Not Language-Specific"]}}, "267": {"name": "Privilege Defined With Unsafe Actions", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.", "phase": ["Architecture and Design", "Operation"]}, {"description": "Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the s...", "phase": ["Architecture and Design", "Operation"]}], "observed_examples": [{"cve": "CVE-2002-1981", "description": "Roles have access to dangerous procedures (Accessible entities)."}, {"cve": "CVE-2002-1671", "description": "Untrusted object/method gets access to clipboard (Accessible entities)."}, {"cve": "CVE-2004-2204", "description": "Gain privileges using functions/tags that should be restricted (Accessible entities)."}, {"cve": "CVE-2000-0315", "description": "Traceroute program allows unprivileged users to modify source address of packet (Accessible entities)."}, {"cve": "CVE-2004-0380", "description": "Bypass domain restrictions using a particular file that references unsafe URI schemes (Accessible entities)."}], "platforms": {"languages": ["Not Language-Specific"]}}, "268": {"name": "Privilege Chaining", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Two distinct privileges, roles, capabilities, or rights can be combined in a way that allows an entity to perform unsafe actions that would not be allowed without that combination.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Consider following the principle of separation of privilege. Require multiple conditions to be met before permitting access to a system resource.", "phase": ["Architecture and Design"]}, {"description": "Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.", "phase": ["Architecture and Design", "Operation"]}, {"description": "Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the s...", "phase": ["Architecture and Design", "Operation"]}], "observed_examples": [{"cve": "CVE-2005-1736", "description": "Chaining of user rights."}, {"cve": "CVE-2002-1772", "description": "Gain certain rights via privilege chaining in alternate channel."}, {"cve": "CVE-2005-1973", "description": "Application is allowed to assign extra permissions to itself."}, {"cve": "CVE-2003-0640", "description": "\"operator\" user can overwrite usernames and passwords to gain admin privileges."}], "platforms": {"languages": ["Not Language-Specific"]}}, "269": {"name": "Improper Privilege Management", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.", "phase": ["Architecture and Design", "Operation"]}, {"description": "Follow the principle of least privilege when assigning access rights to entities in a software system.", "phase": ["Architecture and Design"]}, {"description": "Consider following the principle of separation of privilege. Require multiple conditions to be met before permitting access to a system resource.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2001-1555", "description": "Terminal privileges are not reset when a user logs out."}, {"cve": "CVE-2001-1514", "description": "Does not properly pass security context to child processes in certain cases, allows privilege escalation."}, {"cve": "CVE-2001-0128", "description": "Does not properly compute roles."}, {"cve": "CVE-1999-1193", "description": "untrusted user placed in unix \"wheel\" group"}, {"cve": "CVE-2005-2741", "description": "Product allows users to grant themselves certain rights that can be used to escalate privileges."}], "platforms": {"languages": ["Not Language-Specific"]}}, "27": {"name": "Path Traversal: 'dir/../../filename'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize multiple internal \"../\" sequences that can resolve to a location that is outside of that directory.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2002-0298", "description": "Server allows remote attackers to cause a denial of service via certain HTTP GET requests containing a %2e%2e (encoded dot-dot), several \"/../\" sequen..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "270": {"name": "Privilege Context Switching Error", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.", "phase": ["Architecture and Design", "Operation"]}, {"description": "Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the s...", "phase": ["Architecture and Design", "Operation"]}, {"description": "Consider following the principle of separation of privilege. Require multiple conditions to be met before permitting access to a system resource.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2002-1688", "description": "Web browser cross domain problem when user hits \"back\" button."}, {"cve": "CVE-2003-1026", "description": "Web browser cross domain problem when user hits \"back\" button."}, {"cve": "CVE-2002-1770", "description": "Cross-domain issue - third party product passes code to web browser, which executes it in unsafe zone."}, {"cve": "CVE-2005-2263", "description": "Run callback in different security context after it has been changed from untrusted to trusted. * note that \"context switch before actions are complet..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "271": {"name": "Privilege Dropping / Lowering Errors", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not drop privileges before passing control of a resource to an actor that does not have those privileges.", "extended_description": "In some contexts, a system executing with elevated permissions will hand off a process/file/etc. to another process or user. If the privileges of an entity are not reduced, then elevated privileges are spread throughout a system and possibly to an attacker.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Access Control", "Non-Repudiation"], "impact": ["Gain Privileges or Assume Identity", "Hide Activities"]}], "mitigations": [{"description": "Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.", "phase": ["Architecture and Design", "Operation"]}, {"description": "Consider following the principle of separation of privilege. Require multiple conditions to be met before permitting access to a system resource.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2000-1213", "description": "Program does not drop privileges after acquiring the raw socket."}, {"cve": "CVE-2001-0559", "description": "Setuid program does not drop privileges after a parsing error occurs, then calls another program to handle the error."}, {"cve": "CVE-2001-0787", "description": "Does not drop privileges in related groups when lowering privileges."}, {"cve": "CVE-2002-0080", "description": "Does not drop privileges in related groups when lowering privileges."}, {"cve": "CVE-2001-1029", "description": "Does not drop privileges before determining access to certain files."}], "platforms": {"languages": ["Not Language-Specific"]}}, "272": {"name": "Least Privilege Violation", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The elevated privilege level required to perform operations such as chroot() should be dropped immediately after the operation is performed.", "consequences": [{"scope": ["Access Control", "Confidentiality"], "impact": ["Gain Privileges or Assume Identity", "Read Application Data", "Read Files or Directories"]}], "mitigations": [{"description": "Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.", "phase": ["Architecture and Design", "Operation"]}, {"description": "Follow the principle of least privilege when assigning access rights to entities in a software system.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Dynamic Analysis with Automated Results Interpretation"}, {"method": "Manual Static Analysis - Source Code"}], "platforms": {"languages": ["Not Language-Specific"]}}, "273": {"name": "Improper Check for Dropped Privileges", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.", "extended_description": "If the drop fails, the product will continue to run with the raised privileges, which might provide additional access to unprivileged users.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Access Control", "Non-Repudiation"], "impact": ["Gain Privileges or Assume Identity", "Hide Activities"]}], "mitigations": [{"description": "Check the results of all functions that return a value and verify that the value is expected.", "phase": ["Implementation"]}, {"description": "In Windows, make sure that the process token has the SeImpersonatePrivilege(Microsoft Server 2003). Code that relies on impersonation for security must ensure that the impersonation succeeded, i.e., that a proper privilege demotion happened.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2006-4447", "description": "Program does not check return value when invoking functions to drop privileges, which could leave users with higher privileges than expected by forcin..."}, {"cve": "CVE-2006-2916", "description": "Program does not check return value when invoking functions to drop privileges, which could leave users with higher privileges than expected by forcin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "274": {"name": "Improper Handling of Insufficient Privileges", "abstraction": "Base", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not handle or incorrectly handles when it has insufficient privileges to perform an operation, leading to resultant weaknesses.", "consequences": [{"scope": ["Other"], "impact": ["Other", "Alter Execution Logic"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2001-1564", "description": "System limits are not properly enforced after privileges are dropped."}, {"cve": "CVE-2005-3286", "description": "Firewall crashes when it can't read a critical memory block that was protected by a malicious process."}, {"cve": "CVE-2005-1641", "description": "Does not give admin sufficient privileges to overcome otherwise legitimate user actions."}], "platforms": {"languages": ["Not Language-Specific"]}}, "276": {"name": "Incorrect Default Permissions", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "During installation, installed file permissions are set to allow anyone to modify those files.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data"]}], "mitigations": [{"description": "The architecture needs to access and modification attributes for files to only those users who actually require those actions.", "phase": ["Architecture and Design", "Operation"]}], "detection_methods": [{"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Manual Static Analysis - Binary or Bytecode"}, {"method": "Dynamic Analysis with Automated Results Interpretation"}], "observed_examples": [{"cve": "CVE-2005-1941", "description": "Executables installed world-writable."}, {"cve": "CVE-2002-1713", "description": "Home directories installed world-readable."}, {"cve": "CVE-2001-1550", "description": "World-writable log files allow information loss; world-readable file has cleartext passwords."}, {"cve": "CVE-2002-1711", "description": "World-readable directory."}, {"cve": "CVE-2002-1844", "description": "Windows product uses insecure permissions when installing on Solaris (genesis: port error)."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "ICS/OT"]}}, "277": {"name": "Insecure Inherited Permissions", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "A product defines a set of insecure permissions that are inherited by objects that are created by the program.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data"]}], "mitigations": [{"description": "Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.", "phase": ["Architecture and Design", "Operation"]}], "observed_examples": [{"cve": "CVE-2005-1841", "description": "User's umask is used when creating temp files."}, {"cve": "CVE-2002-1786", "description": "Insecure umask for core dumps [is the umask preserved or assigned?]."}], "platforms": {"languages": ["Not Language-Specific"]}}, "278": {"name": "Insecure Preserved Inherited Permissions", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "A product inherits a set of insecure permissions for an object, e.g. when copying from an archive file, without user awareness or involvement.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data"]}], "mitigations": [{"description": "Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.", "phase": ["Architecture and Design", "Operation"]}], "observed_examples": [{"cve": "CVE-2005-1724", "description": "Does not obey specified permissions when exporting."}], "platforms": {"languages": ["Not Language-Specific"]}}, "279": {"name": "Incorrect Execution-Assigned Permissions", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "While it is executing, the product sets the permissions of an object in a way that violates the intended permissions that have been specified by the user.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data"]}], "mitigations": [{"description": "Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.", "phase": ["Architecture and Design", "Operation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2002-0265", "description": "Log files opened read/write."}, {"cve": "CVE-2003-0876", "description": "Log files opened read/write."}, {"cve": "CVE-2002-1694", "description": "Log files opened read/write."}], "platforms": {"languages": ["Not Language-Specific"]}}, "28": {"name": "Path Traversal: '..\\filedir'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize \"..\\\" sequences that can resolve to a location that is outside of that directory.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2002-0661", "description": "\"\\\" not in denylist for web server, allowing path traversal attacks when the server is run in Windows and other OSes."}, {"cve": "CVE-2002-0946", "description": "Arbitrary files may be read files via ..\\ (dot dot) sequences in an HTTP request."}, {"cve": "CVE-2002-1042", "description": "Directory traversal vulnerability in search engine for web server allows remote attackers to read arbitrary files via \"..\\\" sequences in queries."}, {"cve": "CVE-2002-1209", "description": "Directory traversal vulnerability in FTP server allows remote attackers to read arbitrary files via \"..\\\" sequences in a GET request."}, {"cve": "CVE-2002-1178", "description": "Directory traversal vulnerability in servlet allows remote attackers to execute arbitrary commands via \"..\\\" sequences in an HTTP request."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "280": {"name": "Improper Handling of Insufficient Permissions or Privileges ", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.", "consequences": [{"scope": ["Other"], "impact": ["Other", "Alter Execution Logic"]}], "mitigations": [{"description": "Always check to see if you have successfully accessed a resource or system functionality, and use proper error handling if it is unsuccessful. Do this even when you are operating in a highly privileged mode, because errors or environmental conditions might still cause a failure. For example, environ...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2003-0501", "description": "Special file system allows attackers to prevent ownership/permission change of certain entries by opening the entries before calling a setuid program."}, {"cve": "CVE-2004-0148", "description": "FTP server places a user in the root directory when the user's permissions prevent access to the their own home directory."}], "platforms": {"languages": ["Not Language-Specific"]}}, "281": {"name": "Improper Preservation of Permissions", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data"]}], "observed_examples": [{"cve": "CVE-2002-2323", "description": "Incorrect ACLs used when restoring backups from directories that use symbolic links."}, {"cve": "CVE-2001-1515", "description": "Automatic modification of permissions inherited from another file system."}, {"cve": "CVE-2005-1920", "description": "Permissions on backup file are created with defaults, possibly less secure than original file."}, {"cve": "CVE-2001-0195", "description": "File is made world-readable when being cloned."}], "platforms": {"languages": ["Not Language-Specific"]}}, "282": {"name": "Improper Ownership Management", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product assigns the wrong ownership, or does not properly verify the ownership, of an object or resource.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.", "phase": ["Architecture and Design", "Operation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-1999-1125", "description": "Program runs setuid root but relies on a configuration file owned by a non-root user."}], "platforms": {"languages": ["Not Language-Specific"]}}, "283": {"name": "Unverified Ownership", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly verify that a critical resource is owned by the proper entity.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.", "phase": ["Architecture and Design", "Operation"]}, {"description": "Consider following the principle of separation of privilege. Require multiple conditions to be met before permitting access to a system resource.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2001-0178", "description": "Program does not verify the owner of a UNIX socket that is used for sending a password."}, {"cve": "CVE-2004-2012", "description": "Owner of special device not checked, allowing root."}], "platforms": {"languages": ["Not Language-Specific"]}}, "284": {"name": "Improper Access Control", "abstraction": "Pillar", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.", "phase": ["Architecture and Design", "Operation"]}], "observed_examples": [{"cve": "CVE-2023-26463", "description": "Chain: IPSec VPN product uses the same variable for multiple purposes in the same function (CWE-1109), leading to incorrect access control (CWE-284) a..."}, {"cve": "CVE-2022-24985", "description": "A form hosting website only checks the session authentication status for a single form, making it possible to bypass authentication when there are mul..."}, {"cve": "CVE-2022-29238", "description": "Access-control setting in web-based document collaboration tool is not properly implemented by the code, which prevents listing hidden directories but..."}, {"cve": "CVE-2022-23607", "description": "Python-based HTTP library did not scope cookies to a particular domain such that \"supercookies\" could be sent to any domain on redirect"}, {"cve": "CVE-2021-21972", "description": "Chain: Cloud computing virtualization platform does not require authentication for upload of a tar format file (CWE-306), then uses .. path traversal ..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "ICS/OT", "Web Based"]}}, "285": {"name": "Improper Authorization", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data", "Read Files or Directories"]}, {"scope": ["Integrity"], "impact": ["Modify Application Data", "Modify Files or Directories"]}, {"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Ensure that you perform access control checks related to your business logic. These checks may be different than the access control checks that you apply to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for med...", "phase": ["Architecture and Design"]}, {"description": "Use the access control capabilities of your operating system and server environment and define your access control lists accordingly. Use a \"default deny\" policy when defining these ACLs.", "phase": ["System Configuration", "Installation"]}], "detection_methods": [{"method": "Automated Static Analysis"}, {"method": "Automated Dynamic Analysis", "description": "Automated dynamic analysis may find many or all possible interfaces that do not require authorization, but manual analysis is required to determine if the lack of authorization violates business logic"}, {"method": "Manual Analysis"}], "observed_examples": [{"cve": "CVE-2022-24730", "description": "Go-based continuous deployment product does not check that a user has certain privileges to update or create an app, allowing adversaries to read sens..."}, {"cve": "CVE-2009-3168", "description": "Web application does not restrict access to admin scripts, allowing authenticated users to reset administrative passwords."}, {"cve": "CVE-2009-2960", "description": "Web application does not restrict access to admin scripts, allowing authenticated users to modify passwords of other users."}, {"cve": "CVE-2009-3597", "description": "Web application stores database file under the web root with insufficient access control (CWE-219), allowing direct request."}, {"cve": "CVE-2009-2282", "description": "Terminal server does not check authorization for guest access."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Server", "Database Server"]}}, "286": {"name": "Incorrect User Management", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not properly manage a user within its environment.", "extended_description": "Users can be assigned to the wrong group (class) of permissions resulting in unintended access rights to sensitive objects.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "observed_examples": [{"cve": "CVE-2022-36109", "description": "Containerization product does not record a user's supplementary group ID, allowing bypass of group restrictions."}, {"cve": "CVE-1999-1193", "description": "Operating system assigns user to privileged wheel group, allowing the user to gain root privileges."}], "platforms": {"languages": ["Not Language-Specific"]}}, "287": {"name": "Improper Authentication", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability", "Access Control"], "impact": ["Read Application Data", "Gain Privileges or Assume Identity", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Use an authentication framework or library such as the OWASP ESAPI Authentication feature.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis"}, {"method": "Manual Static Analysis"}, {"method": "Manual Static Analysis - Binary or Bytecode"}], "observed_examples": [{"cve": "CVE-2024-11680", "description": "File-sharing PHP product does not check if user is logged in during requests for PHP library files under an includes/ directory, allowing configuratio..."}, {"cve": "CVE-2022-35248", "description": "Chat application skips validation when Central Authentication Service\n\t\t\t (CAS) is enabled, effectively removing the second factor from\n\t\t\t two-factor..."}, {"cve": "CVE-2022-36436", "description": "Python-based authentication proxy does not enforce password authentication during the initial handshake, allowing the client to bypass authentication ..."}, {"cve": "CVE-2022-30034", "description": "Chain: Web UI for a Python RPC framework does not use regex anchors to validate user login emails (CWE-777), potentially allowing bypass of OAuth (CWE..."}, {"cve": "CVE-2022-29951", "description": "TCP-based protocol in Programmable Logic Controller (PLC) has no authentication."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based", "ICS/OT"]}}, "288": {"name": "Authentication Bypass Using an Alternate Path or Channel", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product requires authentication, but the product has an alternate path or channel that does not require authentication.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Funnel all access through a single choke point to simplify how users can access a resource. For every access, perform a check to determine if the user has permissions to access the resource.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2000-1179", "description": "Router allows remote attackers to read system logs without authentication by directly connecting to the login screen and typing certain control charac..."}, {"cve": "CVE-1999-1454", "description": "Attackers with physical access to the machine may bypass the password prompt by pressing the ESC (Escape) key."}, {"cve": "CVE-1999-1077", "description": "OS allows local attackers to bypass the password protection of idled sessions via the programmer's switch or CMD-PWR keyboard sequence, which brings u..."}, {"cve": "CVE-2003-0304", "description": "Direct request of installation file allows attacker to create administrator accounts."}, {"cve": "CVE-2002-0870", "description": "Attackers may gain additional privileges by directly requesting the web management URL."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "289": {"name": "Authentication Bypass by Alternate Name", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product performs authentication based on the name of a resource being accessed, or the name of the actor performing the access, but it does not properly check all possible names for that resource or actor.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Avoid making decisions based on names of resources (e.g. files) if those resources can have alternate names.", "phase": ["Architecture and Design"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2003-0317", "description": "Protection mechanism that restricts URL access can be bypassed using URL encoding."}, {"cve": "CVE-2004-0847", "description": "web framework for .NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) \"\\\" (..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "29": {"name": "Path Traversal: '\\..\\filename'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\\..\\filename' (leading backslash dot dot) sequences that can resolve to a location that is outside of that directory.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2002-1987", "description": "Protection mechanism checks for \"/..\" but doesn't account for Windows-specific \"\\..\" allowing read of arbitrary files."}, {"cve": "CVE-2005-2142", "description": "Directory traversal vulnerability in FTP server allows remote authenticated attackers to list arbitrary directories via a \"\\..\" sequence in an LS comm..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "290": {"name": "Authentication Bypass by Spoofing", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}], "observed_examples": [{"cve": "CVE-2022-30319", "description": "S-bus functionality in a home automation product performs access control using an IP allowlist, which can be bypassed by a forged IP address."}, {"cve": "CVE-2009-1048", "description": "VOIP product allows authentication bypass using 127.0.0.1 in the Host header."}], "platforms": {"languages": ["Not Language-Specific"]}}, "291": {"name": "Reliance on IP Address for Authentication", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses an IP address for authentication.", "extended_description": "IP addresses can be easily spoofed. Attackers can forge the source IP address of the packets they send, but response packets will return to the forged IP address. To see the response packets, the attacker has to sniff the traffic between the victim machine and the forged IP address. In order to accomplish the required sniffing, attackers typically attempt to locate themselves on the same subnet as the victim machine. Attackers may be able to circumvent this requirement by using source routing, b...", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control", "Non-Repudiation"], "impact": ["Hide Activities", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Use other means of identity verification that cannot be simply spoofed. Possibilities include a username/password or certificate.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2022-30319", "description": "S-bus functionality in a home automation product performs access control using an IP allowlist, which can be bypassed by a forged IP address."}], "platforms": {"languages": ["Not Language-Specific"]}}, "292": {"name": "DEPRECATED: Trusting Self-reported DNS Name", "abstraction": "Variant", "mapping": "PROHIBITED", "structure": "Simple", "description": "This entry has been deprecated because it was a duplicate of CWE-350. All content has been transferred to CWE-350."}, "293": {"name": "Using Referer Field for Authentication", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The referer field in HTTP requests can be easily modified and, as such, is not a valid means of message integrity checking.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "In order to usefully check if a given action is authorized, some means of strong authentication and method protection must be used. Use other means of authorization that cannot be simply spoofed. Possibilities include a username/password or certificate.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "294": {"name": "Authentication Bypass by Capture-replay", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).", "extended_description": "Capture-replay attacks are common and can be difficult to defeat without cryptography. They are a subset of network injection attacks that rely on observing previously-sent valid commands, then changing them slightly if necessary and resending the same commands to the server.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Utilize some sequence or time stamping functionality along with a checksum which takes this into account in order to ensure that messages can be parsed only once.", "phase": ["Architecture and Design"]}, {"description": "Since any attacker who can listen to traffic can see sequence numbers, it is necessary to sign messages with some kind of cryptography to ensure that sequence numbers are not simply doctored along with content.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2005-3435", "description": "product authentication succeeds if user-provided MD5 hash matches the hash in its database; this can be subjected to replay attacks."}, {"cve": "CVE-2007-4961", "description": "Chain: cleartext transmission of the MD5 hash of password (CWE-319) enables attacks against a server that is susceptible to replay (CWE-294)."}], "platforms": {"languages": ["Not Language-Specific"]}}, "295": {"name": "Improper Certificate Validation", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not validate, or incorrectly validates, a certificate.", "consequences": [{"scope": ["Integrity", "Authentication"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Certificates should be carefully managed and checked to assure that data are encrypted with the intended owner's public key.", "phase": ["Architecture and Design", "Implementation"]}, {"description": "If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the hostname.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Manual Static Analysis - Binary or Bytecode"}, {"method": "Dynamic Analysis with Automated Results Interpretation"}], "observed_examples": [{"cve": "CVE-2019-12496", "description": "A Go framework for robotics, drones, and IoT devices skips verification of root CA certificates by default."}, {"cve": "CVE-2014-1266", "description": "Chain: incorrect \"goto\" in Apple SSL product bypasses certificate validation, allowing Adversary-in-the-Middle (AITM) attack (Apple \"goto fail\" bug). ..."}, {"cve": "CVE-2021-22909", "description": "Chain: router's firmware update procedure uses curl with \"-k\" (insecure) option that disables certificate validation (CWE-295), allowing adversary-in-..."}, {"cve": "CVE-2008-4989", "description": "Verification function trusts certificate chains in which the last certificate is self-signed."}, {"cve": "CVE-2012-5821", "description": "Web browser uses a TLS-related function incorrectly, preventing it from verifying that a server's certificate is signed by a trusted certification aut..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based", "Mobile"]}}, "296": {"name": "Improper Following of a Certificate's Chain of Trust", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not follow, or incorrectly follows, the chain of trust for a certificate back to a trusted root certificate, resulting in incorrect trust of any resource that is associated with that certificate.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Non-Repudiation"], "impact": ["Hide Activities"]}, {"scope": ["Integrity", "Confidentiality", "Availability", "Access Control"], "impact": ["Gain Privileges or Assume Identity", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Ensure that proper certificate checking is included in the system design.", "phase": ["Architecture and Design"]}, {"description": "Understand, and properly implement all checks necessary to ensure the integrity of certificate trust integrity.", "phase": ["Implementation"]}, {"description": "If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the full chain of trust.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2016-2402", "description": "Server allows bypass of certificate pinning by sending a chain of trust that includes a trusted CA that is not pinned."}, {"cve": "CVE-2008-4989", "description": "Verification function trusts certificate chains in which the last certificate is self-signed."}, {"cve": "CVE-2012-5821", "description": "Chain: Web browser uses a TLS-related function incorrectly, preventing it from verifying that a server's certificate is signed by a trusted certificat..."}, {"cve": "CVE-2009-3046", "description": "Web browser does not check if any intermediate certificates are revoked."}, {"cve": "CVE-2009-0265", "description": "chain: DNS server does not correctly check return value from the OpenSSL EVP_VerifyFinal function allows bypass of validation of the certificate chain..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "297": {"name": "Improper Validation of Certificate with Host Mismatch", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Authentication", "Other"], "impact": ["Other"]}], "mitigations": [{"description": "Fully check the hostname of the certificate and provide the user with adequate information about the nature of the problem and how to proceed.", "phase": ["Architecture and Design"]}, {"description": "If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the hostname.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Dynamic Analysis with Manual Results Interpretation", "description": "Set up an untrusted endpoint (e.g. a server) with which the product will connect.  Create a test certificate that uses an invalid hostname but is signed by a trusted CA and provide this certificate fr..."}, {"method": "Black Box", "description": "When Certificate Pinning is being used in a mobile application, consider using a tool such as Spinner [REF-955].  This methodology might be extensible to other technologies."}], "observed_examples": [{"cve": "CVE-2012-5810", "description": "Mobile banking application does not verify hostname, leading to financial loss."}, {"cve": "CVE-2012-5811", "description": "Mobile application for printing documents does not verify hostname, allowing attackers to read sensitive documents."}, {"cve": "CVE-2012-5807", "description": "Software for electronic checking does not verify hostname, leading to financial loss."}, {"cve": "CVE-2012-3446", "description": "Cloud-support library written in Python uses incorrect regular expression when matching hostname."}, {"cve": "CVE-2009-2408", "description": "Web browser does not correctly handle '\\0' character (NUL) in Common Name, allowing spoofing of https sites."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Mobile", "Web Based"]}}, "298": {"name": "Improper Validation of Certificate Expiration", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "A certificate expiration is not validated or is incorrectly validated, so trust may be assigned to certificates that have been abandoned due to age.", "extended_description": "When the expiration of a certificate is not taken into account, no trust has necessarily been conveyed through it. Therefore, the validity of the certificate cannot be verified and all benefit of the certificate is lost.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Other"]}, {"scope": ["Authentication", "Other"], "impact": ["Other"]}], "mitigations": [{"description": "Check for expired certificates and provide the user with adequate information about the nature of the problem and how to proceed.", "phase": ["Architecture and Design"]}, {"description": "If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the expiration.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "299": {"name": "Improper Check for Certificate Revocation", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not check or incorrectly checks the revocation status of a certificate, which may cause it to use a certificate that has been compromised.", "extended_description": "An improper check for certificate revocation is a far more serious flaw than related certificate failures. This is because the use of any revoked certificate is almost certainly malicious. The most common reason for certificate revocation is compromise of the system in question, with the result that no legitimate servers will be using a revoked certificate, unless they are sorely out of sync.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Integrity", "Other"], "impact": ["Other"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Ensure that certificates are checked for revoked status.", "phase": ["Architecture and Design"]}, {"description": "If certificate pinning is being used, ensure that all relevant properties of the certificate are fully validated before the certificate is pinned, including the revoked status.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2011-2014", "description": "LDAP-over-SSL implementation does not check Certificate Revocation List (CRL), allowing spoofing using a revoked certificate."}, {"cve": "CVE-2011-0199", "description": "Operating system does not check Certificate Revocation List (CRL) in some cases, allowing spoofing using a revoked certificate."}, {"cve": "CVE-2010-5185", "description": "Antivirus product does not check whether certificates from signed executables have been revoked."}, {"cve": "CVE-2009-3046", "description": "Web browser does not check if any intermediate certificates are revoked."}, {"cve": "CVE-2009-0161", "description": "chain: Ruby module for OCSP misinterprets a response, preventing detection of a revoked certificate."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "30": {"name": "Path Traversal: '\\dir\\..\\filename'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\\dir\\..\\filename' (leading backslash dot dot) sequences that can resolve to a location that is outside of that directory.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2002-1987", "description": "Protection mechanism checks for \"/..\" but doesn't account for Windows-specific \"\\..\" allowing read of arbitrary files."}], "platforms": {"languages": ["Not Language-Specific"]}}, "300": {"name": "Channel Accessible by Non-Endpoint", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not adequately verify the identity of actors at both ends of a communication channel, or does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an endpoint.", "extended_description": "In order to establish secure communication between two parties, it is often important to adequately verify the identity of entities at each end of the communication channel. Inadequate or inconsistent verification may result in insufficient or incorrect identification of either communicating entity. This can have negative consequences such as misplaced trust in the entity at the other end of the channel. An attacker can leverage this by interposing between the communicating entities and masquera...", "consequences": [{"scope": ["Confidentiality", "Integrity", "Access Control"], "impact": ["Read Application Data", "Modify Application Data", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Always fully authenticate both ends of any communications channel.", "phase": ["Implementation"]}, {"description": "Adhere to the principle of complete mediation.", "phase": ["Architecture and Design"]}, {"description": "A certificate binds an identity to a cryptographic key to authenticate a communicating party. Often, the certificate takes the encrypted form of the hash of the identity of the subject, the public key, and information such as time of issue or expiration using the issuer's private key. The certificat...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Dynamic Analysis", "description": "Some tools can act as proxy servers that allow the tester to intercept packets or messages, inspect them, and modify them before sending them to the destination in order to see if the modified packets..."}, {"method": "Automated Dynamic Analysis", "description": "Dynamic Application Security Testing (DAST) tools can be used to detect network traffic without encryption and/or verification. The affected protocol may be subject to Adversary-in-the-Middle attacks...."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2014-1266", "description": "Chain: incorrect \"goto\" in Apple SSL product bypasses certificate validation, allowing Adversary-in-the-Middle (AITM) attack (Apple \"goto fail\" bug). ..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "301": {"name": "Reflection Attack in an Authentication Protocol", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Simple authentication protocols are subject to reflection attacks if a malicious user can use the target machine to impersonate a trusted user.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Use different keys for the initiator and responder or of a different type of challenge for the initiator and responder.", "phase": ["Architecture and Design"]}, {"description": "Let the initiator prove its identity before proceeding.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2005-3435", "description": "product authentication succeeds if user-provided MD5 hash matches the hash in its database; this can be subjected to replay attacks."}], "platforms": {"languages": ["Not Language-Specific"]}}, "302": {"name": "Authentication Bypass by Assumed-Immutable Data", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Implement proper protection for immutable data (e.g. environment variable, hidden form fields, etc.)", "phase": ["Architecture and Design", "Operation", "Implementation"]}], "observed_examples": [{"cve": "CVE-2002-0367", "description": "DebPloit"}, {"cve": "CVE-2004-0261", "description": "Web auth"}, {"cve": "CVE-2002-1730", "description": "Authentication bypass by setting certain cookies to \"true\"."}, {"cve": "CVE-2002-1734", "description": "Authentication bypass by setting certain cookies to \"true\"."}, {"cve": "CVE-2002-2064", "description": "Admin access by setting a cookie."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "303": {"name": "Incorrect Implementation of Authentication Algorithm", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.", "extended_description": "This incorrect implementation may allow authentication to be bypassed.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "observed_examples": [{"cve": "CVE-2003-0750", "description": "Conditional should have been an 'or' not an 'and'."}], "platforms": {"languages": ["Not Language-Specific"]}}, "304": {"name": "Missing Critical Step in Authentication", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product implements an authentication technique, but it skips a step that weakens the technique.", "extended_description": "Authentication techniques should follow the algorithms that define them exactly, otherwise authentication can be bypassed or more easily subjected to brute force attacks.", "consequences": [{"scope": ["Access Control", "Integrity", "Confidentiality"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity", "Read Application Data", "Execute Unauthorized Code or Commands"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2004-2163", "description": "Shared secret not verified in a RADIUS response packet, allowing authentication bypass by spoofing server replies."}, {"cve": "CVE-2005-3327", "description": "Chain: Authentication bypass by skipping the first startup step as required by the protocol."}], "platforms": {"languages": ["Not Language-Specific"]}}, "305": {"name": "Authentication Bypass by Primary Weakness", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "observed_examples": [{"cve": "CVE-2002-1374", "description": "The provided password is only compared against the first character of the real password."}, {"cve": "CVE-2000-0979", "description": "The password is not properly checked, which allows remote attackers to bypass access controls by sending a 1-byte password that matches the first char..."}, {"cve": "CVE-2001-0088", "description": "Chain: Forum software does not properly initialize an array, which inadvertently sets the password to a single character, allowing remote attackers to..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "306": {"name": "Missing Authentication for Critical Function", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control", "Other"], "impact": ["Gain Privileges or Assume Identity", "Varies by Context"]}], "mitigations": [{"description": "For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-s...", "phase": ["Architecture and Design"]}, {"description": "When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to require strong authentication for users who should be allowed to access the data [REF-1297] [REF-1298] [REF-1302].", "phase": ["Implementation", "System Configuration", "Operation"]}], "detection_methods": [{"method": "Manual Analysis"}, {"method": "Automated Static Analysis"}, {"method": "Manual Static Analysis - Binary or Bytecode"}], "observed_examples": [{"cve": "CVE-2024-11680", "description": "File-sharing PHP product does not check if user is logged in during requests for PHP library files under an includes/ directory, allowing configuratio..."}, {"cve": "CVE-2022-31260", "description": "Chain: a digital asset management program has an undisclosed backdoor in the legacy version of a PHP script (CWE-912) that could allow an unauthentica..."}, {"cve": "CVE-2022-29951", "description": "TCP-based protocol in Programmable Logic Controller (PLC) has no authentication."}, {"cve": "CVE-2022-29952", "description": "Condition Monitor firmware uses a protocol that does not require authentication."}, {"cve": "CVE-2022-30276", "description": "SCADA-based protocol for bridging WAN and LAN traffic has no authentication."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Cloud Computing", "ICS/OT"]}}, "307": {"name": "Improper Restriction of Excessive Authentication Attempts", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "detection_methods": [{"method": "Dynamic Analysis with Automated Results Interpretation"}, {"method": "Dynamic Analysis with Manual Results Interpretation"}, {"method": "Manual Static Analysis - Source Code"}], "observed_examples": [{"cve": "CVE-2019-0039", "description": "the REST API for a network OS has a high limit for number of connections, allowing brute force password guessing"}, {"cve": "CVE-1999-1152", "description": "Product does not disconnect or timeout after multiple failed logins."}, {"cve": "CVE-2001-1291", "description": "Product does not disconnect or timeout after multiple failed logins."}, {"cve": "CVE-2001-0395", "description": "Product does not disconnect or timeout after multiple failed logins."}, {"cve": "CVE-2001-1339", "description": "Product does not disconnect or timeout after multiple failed logins."}], "platforms": {"languages": ["Not Language-Specific"]}}, "308": {"name": "Use of Single-factor Authentication", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses an authentication algorithm that uses a single factor (e.g., a password) in a security context that should require more than one factor.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Use multiple independent authentication schemes, which ensures that -- if one of the methods is compromised -- the system itself is still likely safe from compromise. For this reason, if multiple schemes are possible, they should be implemented and required -- especially if they are easy to use.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2022-35248", "description": "Chat application skips validation when Central Authentication Service\n\t\t\t (CAS) is enabled, effectively removing the second factor from\n\t\t\t two-factor..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "309": {"name": "Use of Password System for Primary Authentication", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The use of password systems as the primary means of authentication may be subject to several flaws or shortcomings, each reducing the effectiveness of the mechanism.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Use a zero-knowledge password protocol, such as SRP.", "phase": ["Architecture and Design"]}, {"description": "Ensure that passwords are stored safely and are not reversible.", "phase": ["Architecture and Design"]}, {"description": "Implement password aging functionality that requires passwords be changed after a certain point.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "31": {"name": "Path Traversal: 'dir\\..\\..\\filename'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize 'dir\\..\\..\\filename' (multiple internal backslash dot dot) sequences that can resolve to a location that is outside of that directory.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2002-0160", "description": "The administration function in Access Control Server allows remote attackers to read HTML, Java class, and image files outside the web root via a \"..\\..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "311": {"name": "Missing Encryption of Sensitive Data", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not encrypt sensitive or critical information before storage or transmission.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Confidentiality", "Integrity"], "impact": ["Modify Application Data"]}], "mitigations": [{"description": "Clearly specify which data or resources are valuable enough that they should be protected by encryption. Require that any transmission or storage of this data/resource should use well-vetted encryption algorithms.", "phase": ["Requirements"]}, {"description": "When using industry-approved techniques, use them correctly. Don't cut corners by skipping resource-intensive steps (CWE-325). These steps are often essential for preventing common attacks.", "phase": ["Implementation", "Architecture and Design"]}, {"description": "Use naming conventions and strong types to make it easier to spot when sensitive data is being used. When creating structures, objects, or other complex entities, separate the sensitive and non-sensitive data as much as possible.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Manual Analysis", "description": "The characterizaton of sensitive data often requires domain-specific understanding, so manual methods are useful. However, manual efforts might not achieve desired code coverage within limited time co..."}, {"method": "Automated Analysis", "description": "Automated measurement of the entropy of an input/output source may indicate the use or lack of encryption, but human analysis is still required to distinguish intentionally-unencrypted data (e.g. meta..."}, {"method": "Manual Static Analysis - Binary or Bytecode"}], "observed_examples": [{"cve": "CVE-2022-26390", "description": "wireless battery product stores credentials and Personal Health Information (PHI) without encryption"}, {"cve": "CVE-2009-2272", "description": "password and username stored in cleartext in a cookie"}, {"cve": "CVE-2009-1466", "description": "password stored in cleartext in a file with insecure permissions"}, {"cve": "CVE-2009-0152", "description": "chat program disables SSL in some circumstances even when the user says to use SSL."}, {"cve": "CVE-2009-1603", "description": "Chain: product uses an incorrect public exponent when generating an RSA key, which effectively disables the encryption"}], "platforms": {"languages": ["Not Language-Specific"]}}, "312": {"name": "Cleartext Storage of Sensitive Information", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to encrypt the data at rest. [REF-1297] [REF-1299] [REF-1301]", "phase": ["Implementation", "System Configuration", "Operation"]}, {"description": "In some systems/environments such as cloud, the use of \"double encryption\" (at both the software and hardware layer) might be required, and the developer might be solely responsible for both layers, instead of shared responsibility with the administrator of the broader system/environment.", "phase": ["Implementation", "System Configuration", "Operation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-26390", "description": "wireless battery product stores credentials and Personal Health Information (PHI) without encryption"}, {"cve": "CVE-2022-30275", "description": "Remote Terminal Unit (RTU) uses a driver that relies on a password stored in plaintext."}, {"cve": "CVE-2009-2272", "description": "password and username stored in cleartext in a cookie"}, {"cve": "CVE-2009-1466", "description": "password stored in cleartext in a file with insecure permissions"}, {"cve": "CVE-2009-0152", "description": "chat program disables SSL in some circumstances even when the user says to use SSL."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Cloud Computing", "ICS/OT", "Mobile"]}}, "313": {"name": "Cleartext Storage in a File or on Disk", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores sensitive information in cleartext in a file, or on disk.", "extended_description": "The sensitive information could be read by attackers with access to the file, or with physical or administrator access to the raw disk. Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2001-1481", "description": "Cleartext credentials in world-readable file."}, {"cve": "CVE-2005-1828", "description": "Password in cleartext in config file."}, {"cve": "CVE-2005-2209", "description": "Password in cleartext in config file."}, {"cve": "CVE-2002-1696", "description": "Decrypted copy of a message written to disk given a combination of options and when user replies to an encrypted message."}, {"cve": "CVE-2004-2397", "description": "Cleartext storage of private key and passphrase in log file when user imports the key."}], "platforms": {"languages": ["Not Language-Specific"]}}, "314": {"name": "Cleartext Storage in the Registry", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores sensitive information in cleartext in the registry.", "extended_description": "Attackers can read the information by accessing the registry key. Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "observed_examples": [{"cve": "CVE-2005-2227", "description": "Cleartext passwords in registry key."}], "platforms": {"languages": ["Not Language-Specific"]}}, "315": {"name": "Cleartext Storage of Sensitive Information in a Cookie", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores sensitive information in cleartext in a cookie.", "extended_description": "Attackers can use widely-available tools to view the cookie and read the sensitive information. Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2002-1800", "description": "Admin password in cleartext in a cookie."}, {"cve": "CVE-2001-1537", "description": "Default configuration has cleartext usernames/passwords in cookie."}, {"cve": "CVE-2001-1536", "description": "Usernames/passwords in cleartext in cookies."}, {"cve": "CVE-2005-2160", "description": "Authentication information stored in cleartext in a cookie."}], "platforms": {"languages": ["Not Language-Specific"]}}, "316": {"name": "Cleartext Storage of Sensitive Information in Memory", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores sensitive information in cleartext in memory.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}], "observed_examples": [{"cve": "CVE-2001-1517", "description": "Sensitive authentication information in cleartext in memory."}, {"cve": "CVE-2001-0984", "description": "Password protector leaves passwords in memory when window is minimized, even when \"clear password when minimized\" is set."}, {"cve": "CVE-2003-0291", "description": "SSH client does not clear credentials from memory."}], "platforms": {"languages": ["Not Language-Specific"]}}, "317": {"name": "Cleartext Storage of Sensitive Information in GUI", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores sensitive information in cleartext within the GUI.", "extended_description": "An attacker can often obtain data from a GUI, even if hidden, by using an API to directly access GUI objects such as windows and menus. Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory", "Read Application Data"]}], "observed_examples": [{"cve": "CVE-2002-1848", "description": "Unencrypted passwords stored in GUI dialog may allow local users to access the passwords."}], "platforms": {"languages": ["Not Language-Specific"]}}, "318": {"name": "Cleartext Storage of Sensitive Information in Executable", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores sensitive information in cleartext in an executable.", "extended_description": "Attackers can reverse engineer binary code to obtain secret data. This is especially easy when the cleartext is plain ASCII. Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "observed_examples": [{"cve": "CVE-2005-1794", "description": "Product stores RSA private key in a DLL and uses it to sign a certificate, allowing spoofing of servers and Adversary-in-the-Middle (AITM) attacks."}, {"cve": "CVE-2001-1527", "description": "administration passwords in cleartext in executable"}], "platforms": {"languages": ["Not Language-Specific"]}}, "319": {"name": "Cleartext Transmission of Sensitive Information", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality"], "impact": ["Read Application Data", "Modify Files or Directories"]}, {"scope": ["Integrity", "Confidentiality"], "impact": ["Read Application Data", "Modify Files or Directories", "Other"]}], "mitigations": [{"description": "Before transmitting, encrypt the data using reliable, confidentiality-protecting cryptographic protocols.", "phase": ["Architecture and Design"]}, {"description": "When using web applications with SSL, use SSL for the entire session from login to logout, not just for the initial login page.", "phase": ["Implementation"]}, {"description": "When designing hardware platforms, ensure that approved encryption algorithms (such as those recommended by NIST) protect paths from security critical data to trusted user applications.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Black Box"}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-29519", "description": "Programmable Logic Controller (PLC) sends sensitive information in plaintext, including passwords and session tokens."}, {"cve": "CVE-2022-30312", "description": "Building Controller uses a protocol that transmits authentication credentials in plaintext."}, {"cve": "CVE-2022-31204", "description": "Programmable Logic Controller (PLC) sends password in plaintext."}, {"cve": "CVE-2002-1949", "description": "Passwords transmitted in cleartext."}, {"cve": "CVE-2008-4122", "description": "Chain: Use of HTTPS cookie without \"secure\" flag causes it to be transmitted across unencrypted HTTP."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Cloud Computing", "Mobile", "ICS/OT", "System on Chip", "Test/Debug Hardware"]}}, "32": {"name": "Path Traversal: '...' (Triple Dot)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '...' (triple dot) sequences that can resolve to a location that is outside of that directory.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2001-0467", "description": "\"\\...\" in web server"}, {"cve": "CVE-2001-0615", "description": "\"...\" or \"....\" in chat server"}, {"cve": "CVE-2001-0963", "description": "\"...\" in cd command in FTP server"}, {"cve": "CVE-2001-1193", "description": "\"...\" in cd command in FTP server"}, {"cve": "CVE-2001-1131", "description": "\"...\" in cd command in FTP server"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "321": {"name": "Use of Hard-coded Cryptographic Key", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a hard-coded, unchangeable cryptographic key.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity", "Read Application Data"]}], "mitigations": [{"description": "Prevention schemes mirror that of hard-coded password storage.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-29960", "description": "Engineering Workstation uses hard-coded cryptographic keys that could allow for unathorized filesystem access and privilege escalation"}, {"cve": "CVE-2022-30271", "description": "Remote Terminal Unit (RTU) uses a hard-coded SSH private key that is likely to be used by default."}, {"cve": "CVE-2020-10884", "description": "WiFi router service has a hard-coded encryption key, allowing root access"}, {"cve": "CVE-2014-2198", "description": "Communications / collaboration product has a hardcoded SSH private key, allowing access to root account"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["ICS/OT"]}}, "322": {"name": "Key Exchange without Entity Authentication", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product performs a key exchange with an actor without verifying the identity of that actor.", "extended_description": "Performing a key exchange will preserve the integrity of the information sent between two entities, but this will not guarantee that the entities are who they claim they are. This may enable an attacker to impersonate an actor by modifying traffic between the two entities.  Typically, this involves a victim client that contacts a malicious server that is impersonating a trusted server. If the client skips authentication or ignores an authentication failure, the malicious server may request authe...", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Ensure that proper authentication is included in the system design.", "phase": ["Architecture and Design"]}, {"description": "Understand and properly implement all checks necessary to ensure the identity of entities involved in encrypted communications.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "323": {"name": "Reusing a Nonce, Key Pair in Encryption", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Nonces should be used for the present occasion and only once.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Refuse to reuse nonce values.", "phase": ["Implementation"]}, {"description": "Use techniques such as requiring incrementing, time based and/or challenge response to assure uniqueness of nonces.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "324": {"name": "Use of a Key Past its Expiration Date", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.", "extended_description": "While the expiration of keys does not necessarily ensure that they are compromised, it is a significant concern that keys which remain in use for prolonged periods of time have a decreasing probability of integrity. For this reason, it is important to replace keys within a period of time proportional to their strength.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Adequate consideration should be put in to the user interface in order to notify users previous to the key's expiration, to explain the importance of new key generation and to walk users through the process as painlessly as possible.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2021-33020", "description": "Picture Archiving and Communication System (PACS) system for hospitals uses a cryptographic key or password past its expiration date"}], "platforms": {"languages": ["Not Language-Specific"]}}, "325": {"name": "Missing Cryptographic Step", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data"]}, {"scope": ["Accountability", "Non-Repudiation"], "impact": ["Hide Activities"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2001-1585", "description": "Missing challenge-response step allows authentication bypass using public key."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "326": {"name": "Inadequate Encryption Strength", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.", "extended_description": "A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.", "consequences": [{"scope": ["Access Control", "Confidentiality"], "impact": ["Bypass Protection Mechanism", "Read Application Data"]}], "mitigations": [{"description": "Use an encryption scheme that is currently considered to be strong by experts in the field.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2001-1546", "description": "Weak encryption"}, {"cve": "CVE-2004-2172", "description": "Weak encryption (chosen plaintext attack)"}, {"cve": "CVE-2002-1682", "description": "Weak encryption"}, {"cve": "CVE-2002-1697", "description": "Weak encryption produces same ciphertext from the same plaintext blocks."}, {"cve": "CVE-2002-1739", "description": "Weak encryption"}], "platforms": {"languages": ["Not Language-Specific"]}}, "327": {"name": "Use of a Broken or Risky Cryptographic Algorithm", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product uses a broken or risky cryptographic algorithm or protocol.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Integrity"], "impact": ["Modify Application Data"]}, {"scope": ["Accountability", "Non-Repudiation"], "impact": ["Hide Activities"]}], "mitigations": [{"description": "Ensure that the design allows one cryptographic algorithm to be replaced with another in the next generation or version. Where possible, use wrappers to make the interfaces uniform. This will make it easier to upgrade to stronger algorithms. With hardware, design the product at the Intellectual Prop...", "phase": ["Architecture and Design"]}, {"description": "Carefully manage and protect cryptographic keys (see CWE-320). If the keys can be guessed or stolen, then the strength of the cryptography itself is irrelevant.", "phase": ["Architecture and Design"]}, {"description": "When using industry-approved techniques, use them correctly. Don't cut corners by skipping resource-intensive steps (CWE-325). These steps are often essential for preventing common attacks.", "phase": ["Implementation", "Architecture and Design"]}], "detection_methods": [{"method": "Automated Analysis", "description": "Automated methods may be useful for recognizing commonly-used libraries or features that have become obsolete."}, {"method": "Manual Analysis", "description": "This weakness can be detected using tools and techniques that require manual (human) analysis, such as penetration testing, threat modeling, and interactive tools that allow the tester to record and m..."}, {"method": "Automated Static Analysis - Binary or Bytecode"}], "observed_examples": [{"cve": "CVE-2022-30273", "description": "SCADA-based protocol supports a legacy encryption mode that uses Tiny Encryption Algorithm (TEA) in ECB mode, which leaks patterns in messages and can..."}, {"cve": "CVE-2022-30320", "description": "Programmable Logic Controller (PLC) uses a protocol with a cryptographically insecure hashing algorithm for passwords."}, {"cve": "CVE-2008-3775", "description": "Product uses \"ROT-25\" to obfuscate the password in the registry."}, {"cve": "CVE-2007-4150", "description": "product only uses \"XOR\" to obfuscate sensitive data"}, {"cve": "CVE-2007-5460", "description": "product only uses \"XOR\" and a fixed key to obfuscate sensitive data"}], "platforms": {"languages": ["Not Language-Specific", "Verilog", "VHDL"], "technologies": ["Not Technology-Specific", "ICS/OT"]}}, "328": {"name": "Use of Weak Hash", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses an algorithm that produces a digest (output value) that does not meet security expectations for a hash function that allows an adversary to reasonably determine the original input (preimage attack), find another input that can produce the same hash (2nd preimage attack), or find multiple inputs that evaluate to the same hash (birthday attack).", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-30320", "description": "Programmable Logic Controller (PLC) uses a protocol with a cryptographically insecure hashing algorithm for passwords."}, {"cve": "CVE-2005-4900", "description": "SHA-1 algorithm is not collision-resistant."}, {"cve": "CVE-2020-25685", "description": "DNS product uses a weak hash (CRC32 or SHA-1) of the query name, allowing attacker to forge responses by computing domain names with the same hash."}, {"cve": "CVE-2012-6707", "description": "blogging product uses MD5-based algorithm for passwords."}, {"cve": "CVE-2019-14855", "description": "forging of certificate signatures using SHA-1 collisions."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["ICS/OT"]}}, "329": {"name": "Generation of Predictable IV with CBC Mode", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product generates and uses a predictable initialization Vector (IV) with Cipher Block Chaining (CBC) Mode, which causes algorithms to be susceptible to dictionary attacks when they are encrypted under the same key.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "NIST recommends two methods of generating unpredictable IVs for CBC mode [REF-1172]. The first is to generate the IV randomly. The second method is to encrypt a nonce with the same key and cipher to be used to encrypt the plaintext. In this case the nonce must be unique but can be predictable, since...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2020-5408", "description": "encryption functionality in an authentication framework uses a fixed null IV with CBC mode, allowing attackers to decrypt traffic in applications that..."}, {"cve": "CVE-2017-17704", "description": "messages for a door-unlocking product use a fixed IV in CBC mode, which is the same after each restart"}, {"cve": "CVE-2017-11133", "description": "application uses AES in CBC mode, but the pseudo-random secret and IV are generated using math.random, which is not cryptographically strong."}, {"cve": "CVE-2007-3528", "description": "Blowfish-CBC implementation constructs an IV where each byte is calculated modulo 8 instead of modulo 256, resulting in less than 12 bits for the effe..."}, {"cve": "CVE-2011-3389", "description": "BEAST attack in SSL 3.0 / TLS 1.0. In CBC mode, chained initialization vectors are non-random, allowing decryption of HTTPS traffic using a chosen pla..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["ICS/OT"]}}, "33": {"name": "Path Traversal: '....' (Multiple Dot)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '....' (multiple dot) sequences that can resolve to a location that is outside of that directory.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2000-0240", "description": "read files via \"/........../\" in URL"}, {"cve": "CVE-2000-0773", "description": "read files via \"....\" in web server"}, {"cve": "CVE-1999-1082", "description": "read files via \"......\" in web server (doubled triple dot?)"}, {"cve": "CVE-2004-2121", "description": "read files via \"......\" in web server (doubled triple dot?)"}, {"cve": "CVE-2001-0491", "description": "multiple attacks using \"..\", \"...\", and \"....\" in different commands"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "330": {"name": "Use of Insufficiently Random Values", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality", "Other"], "impact": ["Other"]}, {"scope": ["Access Control", "Other"], "impact": ["Bypass Protection Mechanism", "Other"]}, {"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Consider a PRNG that re-seeds itself as needed from high quality pseudo-random output sources, such as hardware devices.", "phase": ["Implementation"]}, {"description": "Use automated static analysis tools that target this type of weakness. Many modern techniques use data flow analysis to minimize the number of false positives. This is not a perfect solution, since 100% accuracy and coverage are not feasible.", "phase": ["Testing"]}, {"description": "Use products or modules that conform to FIPS 140-2 [REF-267] to avoid obvious entropy problems. Consult FIPS 140-2 Annex C (\"Approved Random Number Generators\").", "phase": ["Architecture and Design", "Requirements"]}], "detection_methods": [{"method": "Black Box"}, {"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Manual Static Analysis - Binary or Bytecode"}], "observed_examples": [{"cve": "CVE-2021-3692", "description": "PHP framework uses mt_rand() function (Marsenne Twister) when generating tokens"}, {"cve": "CVE-2020-7010", "description": "Cloud application on Kubernetes generates passwords using a weak random number generator based on deployment time."}, {"cve": "CVE-2009-3278", "description": "Crypto product uses rand() library function to generate a recovery key, making it easier to conduct brute force attacks."}, {"cve": "CVE-2009-3238", "description": "Random number generator can repeatedly generate the same value."}, {"cve": "CVE-2009-2367", "description": "Web application generates predictable session IDs, allowing session hijacking."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "331": {"name": "Insufficient Entropy", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.", "consequences": [{"scope": ["Access Control", "Other"], "impact": ["Bypass Protection Mechanism", "Other"]}], "mitigations": [{"description": "Determine the necessary entropy to adequately provide for randomness and predictability. This can be achieved by increasing the number of bits of objects such as keys and seeds.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2001-0950", "description": "Insufficiently random data used to generate session tokens using C rand(). Also, for certificate/key generation, uses a source that does not block whe..."}, {"cve": "CVE-2008-2108", "description": "Chain: insufficient precision (CWE-1339) in\n\t     random-number generator causes some zero bits to be reliably\n\t     generated, reducing the amount of..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "332": {"name": "Insufficient Entropy in PRNG", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The lack of entropy available for, or used by, a Pseudo-Random Number Generator (PRNG) can be a stability and security threat.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Access Control", "Other"], "impact": ["Bypass Protection Mechanism", "Other"]}], "mitigations": [{"description": "Use products or modules that conform to FIPS 140-2 [REF-267] to avoid obvious entropy problems. Consult FIPS 140-2 Annex C (\"Approved Random Number Generators\").", "phase": ["Architecture and Design", "Requirements"]}, {"description": "Consider a PRNG that re-seeds itself as needed from high-quality pseudo-random output, such as hardware devices.", "phase": ["Implementation"]}, {"description": "When deciding which PRNG to use, look at its sources of entropy. Depending on what your security needs are, you may need to use a random number generator that always uses strong random data -- i.e., a random number generator that attempts to be strong but will fail in a weak way or will always provi...", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "[REF-1374]", "description": "Chain: JavaScript-based cryptocurrency library can fall back to the insecure Math.random() function instead of reporting a failure (CWE-392), thus red..."}, {"cve": "CVE-2019-1715", "description": "security product has insufficient entropy in the DRBG, allowing collisions and private key discovery"}], "platforms": {"languages": ["Not Language-Specific"]}}, "333": {"name": "Improper Handling of Insufficient Entropy in TRNG", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "True random number generators (TRNG) generally have a limited source of entropy and therefore can fail or block.", "extended_description": "The rate at which true random numbers can be generated is limited. It is important that one uses them only when they are needed for security.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Rather than failing on a lack of random numbers, it is often preferable to wait for more numbers to be created.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "334": {"name": "Small Space of Random Values", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The number of possible random values is smaller than needed by the product, making it more susceptible to brute force attacks.", "consequences": [{"scope": ["Access Control", "Other"], "impact": ["Bypass Protection Mechanism", "Other"]}], "mitigations": [{"description": "Use products or modules that conform to FIPS 140-2 [REF-267] to avoid obvious entropy problems. Consult FIPS 140-2 Annex C (\"Approved Random Number Generators\").", "phase": ["Architecture and Design", "Requirements"]}], "observed_examples": [{"cve": "CVE-2002-0583", "description": "Product uses 5 alphanumeric characters for filenames of expense claim reports, stored under web root."}, {"cve": "CVE-2002-0903", "description": "Product uses small number of random numbers for a code to approve an action, and also uses predictable new user IDs, allowing attackers to hijack new ..."}, {"cve": "CVE-2003-1230", "description": "SYN cookies implementation only uses 32-bit keys, making it easier to brute force ISN."}, {"cve": "CVE-2004-0230", "description": "Complex predictability / randomness (reduced space)."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "335": {"name": "Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a Pseudo-Random Number Generator (PRNG) but does not correctly manage seeds.", "consequences": [{"scope": ["Access Control", "Other"], "impact": ["Bypass Protection Mechanism", "Other"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2020-7010", "description": "Cloud application on Kubernetes generates passwords using a weak random number generator based on deployment time."}, {"cve": "CVE-2019-11495", "description": "server uses erlang:now() to seed the PRNG, which\n\t\t\t results in a small search space for potential random\n\t\t\t seeds"}, {"cve": "CVE-2018-12520", "description": "Product's PRNG is not seeded for the generation of session IDs"}, {"cve": "CVE-2016-10180", "description": "Router's PIN generation is based on rand(time(0)) seeding."}], "platforms": {"languages": ["Not Language-Specific"]}}, "336": {"name": "Same Seed in Pseudo-Random Number Generator (PRNG)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "A Pseudo-Random Number Generator (PRNG) uses the same seed each time the product is initialized.", "extended_description": "Given the deterministic nature of PRNGs, using the same seed for each initialization will lead to the same output in the same order. If an attacker can guess (or knows) the seed, then the attacker may be able to determine the random numbers that will be produced from the PRNG.", "consequences": [{"scope": ["Other", "Access Control"], "impact": ["Other", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Do not reuse PRNG seeds. Consider a PRNG that periodically re-seeds itself as needed from a high quality pseudo-random output, such as hardware devices.", "phase": ["Architecture and Design"]}, {"description": "Use products or modules that conform to FIPS 140-2 [REF-267] to avoid obvious entropy problems, or use the more recent FIPS 140-3 [REF-1192] if possible.", "phase": ["Architecture and Design", "Requirements"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-39218", "description": "SDK for JavaScript app builder for serverless code uses the same fixed seed for a PRNG, allowing cryptography bypass"}], "platforms": {"languages": ["Not Language-Specific"]}}, "337": {"name": "Predictable Seed in Pseudo-Random Number Generator (PRNG)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "A Pseudo-Random Number Generator (PRNG) is initialized from a predictable seed, such as the process ID or system time.", "extended_description": "The use of predictable seeds significantly reduces the number of possible seeds that an attacker would need to test in order to predict which random numbers will be generated by the PRNG.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Use non-predictable inputs for seed generation."}, {"description": "Use products or modules that conform to FIPS 140-2 [REF-267] to avoid obvious entropy problems, or use the more recent FIPS 140-3 [REF-1192] if possible.", "phase": ["Architecture and Design", "Requirements"]}, {"description": "Use a PRNG that periodically re-seeds itself using input from high-quality sources, such as hardware devices with high entropy. However, do not re-seed too frequently, or else the entropy source might block.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2020-7010", "description": "Cloud application on Kubernetes generates passwords using a weak random number generator based on deployment time."}, {"cve": "CVE-2019-11495", "description": "server uses erlang:now() to seed the PRNG, which\n\t\t\t results in a small search space for potential random\n\t\t\t seeds"}, {"cve": "CVE-2008-0166", "description": "The removal of a couple lines of code caused Debian's OpenSSL Package to only use the current process ID for seeding a PRNG"}, {"cve": "CVE-2016-10180", "description": "Router's PIN generation is based on rand(time(0)) seeding."}, {"cve": "CVE-2018-9057", "description": "cloud provider product uses a non-cryptographically secure PRNG and seeds it with the current time"}], "platforms": {"languages": ["Not Language-Specific"]}}, "338": {"name": "Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a Pseudo-Random Number Generator (PRNG) in a security context, but the PRNG's algorithm is not cryptographically strong.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Use functions or hardware which use a hardware-based random number generation for all crypto. This is the recommended solution. Use CyptGenRandom on Windows, or hw_rand() on Linux.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2021-3692", "description": "PHP framework uses mt_rand() function (Marsenne Twister) when generating tokens"}, {"cve": "CVE-2009-3278", "description": "Crypto product uses rand() library function to generate a recovery key, making it easier to conduct brute force attacks."}, {"cve": "CVE-2009-3238", "description": "Random number generator can repeatedly generate the same value."}, {"cve": "CVE-2009-2367", "description": "Web application generates predictable session IDs, allowing session hijacking."}, {"cve": "CVE-2008-0166", "description": "SSL library uses a weak random number generator that only generates 65,536 unique keys."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "339": {"name": "Small Seed Space in PRNG", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "A Pseudo-Random Number Generator (PRNG) uses a relatively small seed space, which makes it more susceptible to brute force attacks.", "extended_description": "PRNGs are entirely deterministic once seeded, so it should be extremely difficult to guess the seed. If an attacker can collect the outputs of a PRNG and then brute force the seed by trying every possibility to see which seed matches the observed output, then the attacker will know the output of any subsequent calls to the PRNG. A small seed space implies that the attacker will have far fewer possible values to try to exhaust all possibilities.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Use well vetted pseudo-random number generating algorithms with adequate length seeds. Pseudo-random number generators can produce predictable numbers if the generator is known and the seed can be guessed. A 256-bit seed is a good starting point for producing a \"random enough\" number.", "phase": ["Architecture and Design"]}, {"description": "Use products or modules that conform to FIPS 140-2 [REF-267] to avoid obvious entropy problems, or use the more recent FIPS 140-3 [REF-1192] if possible.", "phase": ["Architecture and Design", "Requirements"]}], "observed_examples": [{"cve": "CVE-2019-10908", "description": "product generates passwords via org.apache.commons.lang.RandomStringUtils, which uses java.util.Random internally. This PRNG has only a 48-bit seed."}], "platforms": {"languages": ["Not Language-Specific"]}}, "34": {"name": "Path Traversal: '....//'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '....//' (doubled dot dot slash) sequences that can resolve to a location that is outside of that directory.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis - Source Code"}, {"method": "Architecture or Design Review"}], "observed_examples": [{"cve": "CVE-2004-1670", "description": "Mail server allows remote attackers to create arbitrary directories via a \"..\" or rename arbitrary files via a \"....//\" in user supplied parameters."}], "platforms": {"languages": ["Not Language-Specific"]}}, "340": {"name": "Generation of Predictable Numbers or Identifiers", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product uses a scheme that generates numbers or identifiers that are more predictable than required.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-29330", "description": "Product for administering PBX systems uses predictable identifiers and timestamps for filenames (CWE-340) which allows attackers to access files via d..."}, {"cve": "CVE-2001-1141", "description": "PRNG allows attackers to use the output of small PRNG requests to determine the internal state information, which could be used by attackers to predic..."}, {"cve": "CVE-1999-0074", "description": "Listening TCP ports are sequentially allocated, allowing spoofing attacks."}], "platforms": {"languages": ["Not Language-Specific"]}}, "341": {"name": "Predictable from Observable State", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A number or object is predictable based on observations that the attacker can make about the state of the system or network, such as time, process ID, etc.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Increase the entropy used to seed a PRNG.", "phase": ["Implementation"]}, {"description": "Use products or modules that conform to FIPS 140-2 [REF-267] to avoid obvious entropy problems. Consult FIPS 140-2 Annex C (\"Approved Random Number Generators\").", "phase": ["Architecture and Design", "Requirements"]}, {"description": "Use a PRNG that periodically re-seeds itself using input from high-quality sources, such as hardware devices with high entropy. However, do not re-seed too frequently, or else the entropy source might block.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2024-48445", "description": "Chain: e-commerce app relies on an easily-guessable timestamp (CWE-341) in a weak authentication algorithm (CWE-1390)"}, {"cve": "CVE-2002-0389", "description": "Mail server stores private mail messages with predictable filenames in a world-executable directory, which allows local users to read private mailing ..."}, {"cve": "CVE-2001-1141", "description": "PRNG allows attackers to use the output of small PRNG requests to determine the internal state information, which could be used by attackers to predic..."}, {"cve": "CVE-2000-0335", "description": "DNS resolver library uses predictable IDs, which allows a local attacker to spoof DNS query results."}, {"cve": "CVE-2005-1636", "description": "MFV. predictable filename and insecure permissions allows file modification to execute SQL queries."}], "platforms": {"languages": ["Not Language-Specific"]}}, "342": {"name": "Predictable Exact Value from Previous Values", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "An exact value or random number can be precisely predicted by observing previous values.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Increase the entropy used to seed a PRNG."}, {"description": "Use products or modules that conform to FIPS 140-2 [REF-267] to avoid obvious entropy problems. Consult FIPS 140-2 Annex C (\"Approved Random Number Generators\").", "phase": ["Architecture and Design", "Requirements"]}, {"description": "Use a PRNG that periodically re-seeds itself using input from high-quality sources, such as hardware devices with high entropy. However, do not re-seed too frequently, or else the entropy source might block.", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-1463", "description": "Firewall generates easily predictable initial sequence numbers (ISN), which allows remote attackers to spoof connections."}, {"cve": "CVE-1999-0074", "description": "Listening TCP ports are sequentially allocated, allowing spoofing attacks."}, {"cve": "CVE-1999-0077", "description": "Predictable TCP sequence numbers allow spoofing."}, {"cve": "CVE-2000-0335", "description": "DNS resolver uses predictable IDs, allowing a local user to spoof DNS query results."}], "platforms": {"languages": ["Not Language-Specific"]}}, "343": {"name": "Predictable Value Range from Previous Values", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product's random number generator produces a series of values which, when observed, can be used to infer a relatively small range of possibilities for the next value that could be generated.", "extended_description": "The output of a random number generator should not be predictable based on observations of previous values. In some cases, an attacker cannot predict the exact value that will be produced next, but can narrow down the possibilities significantly. This reduces the amount of effort to perform a brute force attack. For example, suppose the product generates random numbers between 1 and 100, but it always produces a larger value until it reaches 100. If the generator produces an 80, then the attacke...", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Increase the entropy used to seed a PRNG."}, {"description": "Use products or modules that conform to FIPS 140-2 [REF-267] to avoid obvious entropy problems. Consult FIPS 140-2 Annex C (\"Approved Random Number Generators\").", "phase": ["Architecture and Design", "Requirements"]}, {"description": "Use a PRNG that periodically re-seeds itself using input from high-quality sources, such as hardware devices with high entropy. However, do not re-seed too frequently, or else the entropy source might block.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "344": {"name": "Use of Invariant Value in Dynamically Changing Context", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a constant value, name, or reference, but this value can (or should) vary across different environments.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "observed_examples": [{"cve": "CVE-2002-0980", "description": "Component for web browser writes an error message to a known location, which can then be referenced by attackers to process HTML/script in a less rest..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "345": {"name": "Insufficient Verification of Data Authenticity", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Varies by Context", "Unexpected State"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-30260", "description": "Distributed Control System (DCS) does not sign firmware images and only relies on insecure checksums for integrity checks"}, {"cve": "CVE-2022-30267", "description": "Distributed Control System (DCS) does not sign firmware images and only relies on insecure checksums for integrity checks"}, {"cve": "CVE-2022-30272", "description": "Remote Terminal Unit (RTU) does not use signatures for firmware images and relies on insecure checksums"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["ICS/OT"]}}, "346": {"name": "Origin Validation Error", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not properly verify that the source of data or communication is valid.", "consequences": [{"scope": ["Access Control", "Other"], "impact": ["Gain Privileges or Assume Identity", "Varies by Context"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2000-1218", "description": "DNS server can accept DNS updates from hosts that it did not query, leading to cache poisoning"}, {"cve": "CVE-2018-6074", "description": "Browser does not set Mark-of-the-Web (MotW) for a downloaded .EXE file if the name is close to the maximum path length, preventing recording of a zone..."}, {"cve": "CVE-2025-0411", "description": "Zip file extraction program does not propagate Mark-of-the-Web (MotW) metadata to files that are extracted from an Internet-downloaded Zip file"}, {"cve": "CVE-2025-46652", "description": "Zip file extraction program does not propagate Mark-of-the-Web (MotW) metadata to files that are extracted from an Internet-downloaded Zip file"}, {"cve": "CVE-2005-0877", "description": "DNS server can accept DNS updates from hosts that it did not query, leading to cache poisoning"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "347": {"name": "Improper Verification of Cryptographic Signature", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not verify, or incorrectly verifies, the cryptographic signature for data.", "consequences": [{"scope": ["Access Control", "Integrity", "Confidentiality"], "impact": ["Gain Privileges or Assume Identity", "Modify Application Data", "Execute Unauthorized Code or Commands"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2002-1796", "description": "Does not properly verify signatures for \"trusted\" entities."}, {"cve": "CVE-2005-2181", "description": "Insufficient verification allows spoofing."}, {"cve": "CVE-2005-2182", "description": "Insufficient verification allows spoofing."}, {"cve": "CVE-2002-1706", "description": "Accepts a configuration file without a Message Integrity Check (MIC) signature."}], "platforms": {"languages": ["Not Language-Specific"]}}, "348": {"name": "Use of Less Trusted Source", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}], "observed_examples": [{"cve": "CVE-2001-0860", "description": "Product uses IP address provided by a client, instead of obtaining it from the packet headers, allowing easier spoofing."}, {"cve": "CVE-2004-1950", "description": "Web product uses the IP address in the X-Forwarded-For HTTP header instead of a server variable that uses the connecting IP address, allowing filter b..."}, {"cve": "CVE-2001-0908", "description": "Product logs IP address specified by the client instead of obtaining it from the packet headers, allowing information hiding."}, {"cve": "CVE-2006-1126", "description": "PHP application uses IP address from X-Forwarded-For HTTP header, instead of REMOTE_ADDR."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "349": {"name": "Acceptance of Extraneous Untrusted Data With Trusted Data", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.", "consequences": [{"scope": ["Access Control", "Integrity"], "impact": ["Bypass Protection Mechanism", "Modify Application Data"]}], "observed_examples": [{"cve": "CVE-2002-0018", "description": "Does not verify that trusted entity is authoritative for all entities in its response."}, {"cve": "CVE-2006-5462", "description": "use of extra data in a signature allows certificate signature forging"}], "platforms": {"languages": ["Not Language-Specific"]}}, "35": {"name": "Path Traversal: '.../...//'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2005-2169", "description": "chain: \".../...//\" bypasses protection mechanism using regexp's that remove \"../\" resulting in collapse into an unsafe value \"../\" (CWE-182) and resul..."}, {"cve": "CVE-2005-0202", "description": "\".../....///\" bypasses regexp's that remove \"./\" and \"../\""}], "platforms": {"languages": ["Not Language-Specific"]}}, "350": {"name": "Reliance on Reverse DNS Resolution for a Security-Critical Action", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product performs reverse DNS resolution on an IP address to obtain the hostname and make a security decision, but it does not properly ensure that the IP address is truly associated with the hostname.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Use other means of identity verification that cannot be simply spoofed. Possibilities include a username/password or certificate.", "phase": ["Architecture and Design"]}, {"description": "Perform proper forward and reverse DNS lookups to detect DNS spoofing.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2001-1488", "description": "Does not do double-reverse lookup to prevent DNS spoofing."}, {"cve": "CVE-2001-1500", "description": "Does not verify reverse-resolved hostnames in DNS."}, {"cve": "CVE-2000-1221", "description": "Authentication bypass using spoofed reverse-resolved DNS hostnames."}, {"cve": "CVE-2002-0804", "description": "Authentication bypass using spoofed reverse-resolved DNS hostnames."}, {"cve": "CVE-2001-1155", "description": "Filter does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restrictions via DNS s..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "351": {"name": "Insufficient Type Distinction", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly distinguish between different types of elements in a way that leads to insecure behavior.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "observed_examples": [{"cve": "CVE-2005-2260", "description": "Browser user interface does not distinguish between user-initiated and synthetic events."}, {"cve": "CVE-2005-2801", "description": "Product does not compare all required data in two separate elements, causing it to think they are the same, leading to loss of ACLs. Similar to Same N..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "352": {"name": "Cross-Site Request Forgery (CSRF)", "abstraction": "Compound", "mapping": "ALLOWED", "structure": "Composite", "description": "The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Non-Repudiation", "Access Control"], "impact": ["Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Read Application Data", "Modify Application Data", "DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Ensure that the application is free of cross-site scripting issues (CWE-79), because most CSRF defenses can be bypassed using attacker-controlled script.", "phase": ["Implementation"]}, {"description": "Generate a unique nonce for each form, place the nonce into the form, and verify the nonce upon receipt of the form. Be sure that the nonce is not predictable (CWE-330). [REF-332]", "phase": ["Architecture and Design"]}, {"description": "Identify especially dangerous operations. When the user performs a dangerous operation, send a separate confirmation request to ensure that the user intended to perform that operation.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Manual Analysis"}, {"method": "Automated Static Analysis", "description": "CSRF is currently difficult to detect reliably using automated techniques. This is because each application has its own implicit security policy that dictates which requests can be influenced by an ou..."}, {"method": "Automated Static Analysis - Binary or Bytecode"}], "observed_examples": [{"cve": "CVE-2004-1703", "description": "Add user accounts via a URL in an img tag"}, {"cve": "CVE-2004-1995", "description": "Add user accounts via a URL in an img tag"}, {"cve": "CVE-2004-1967", "description": "Arbitrary code execution by specifying the code in a crafted img tag or URL"}, {"cve": "CVE-2004-1842", "description": "Gain administrative privileges via a URL in an img tag"}, {"cve": "CVE-2005-1947", "description": "Delete a victim's information via a URL or an img tag"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "353": {"name": "Missing Support for Integrity Check", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a transmission protocol that does not include a mechanism for verifying the integrity of the data during transmission, such as a checksum.", "extended_description": "If integrity check values or \"checksums\" are omitted from a protocol, there is no way of determining if data has been corrupted in transmission. The lack of checksum functionality in a protocol removes the first application-level check of data that can be used. The end-to-end philosophy of checks states that integrity checks should be performed at the lowest level that they can be completely implemented. Excluding further sanity checks and input validation performed by applications, the protocol...", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Other"]}, {"scope": ["Non-Repudiation", "Other"], "impact": ["Hide Activities", "Other"]}], "mitigations": [{"description": "Add an appropriately sized checksum to the protocol, ensuring that data received may be simply validated before it is parsed and used.", "phase": ["Architecture and Design"]}, {"description": "Ensure that the checksums present in the protocol design are properly implemented and added to each message before it is sent.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "354": {"name": "Improper Validation of Integrity Check Value", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not validate or incorrectly validates the integrity check values or \"checksums\" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.", "extended_description": "Improper validation of checksums before use results in an unnecessary risk that can easily be mitigated. The protocol specification describes the algorithm used for calculating the checksum. It is then a simple matter of implementing the calculation and verifying that the calculated checksum and the received checksum match. Improper verification of the calculated checksum and the received checksum can lead to far greater consequences.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Modify Application Data", "Other"]}, {"scope": ["Integrity", "Other"], "impact": ["Other"]}, {"scope": ["Non-Repudiation", "Other"], "impact": ["Hide Activities", "Other"]}], "mitigations": [{"description": "Ensure that the checksums present in messages are properly checked in accordance with the protocol specification before they are parsed and used.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "356": {"name": "Product UI does not Warn User of Unsafe Actions", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product's user interface does not warn the user before undertaking an unsafe action on behalf of that user. This makes it easier for attackers to trick users into inflicting damage to their system.", "extended_description": "Product systems should warn users that a potentially dangerous action may occur if the user proceeds. For example, if the user downloads a file from an unknown source and attempts to execute the file on their machine, then the application's GUI can indicate that the file is unsafe.", "consequences": [{"scope": ["Non-Repudiation"], "impact": ["Hide Activities"]}], "observed_examples": [{"cve": "CVE-1999-1055", "description": "Product does not warn user when document contains certain dangerous functions or macros."}, {"cve": "CVE-1999-0794", "description": "Product does not warn user when document contains certain dangerous functions or macros."}, {"cve": "CVE-2000-0277", "description": "Product does not warn user when document contains certain dangerous functions or macros."}, {"cve": "CVE-2000-0517", "description": "Product does not warn user about a certificate if it has already been accepted for a different site. Possibly resultant."}, {"cve": "CVE-2005-0602", "description": "File extractor does not warn user if setuid/setgid files could be extracted. Overlaps privileges/permissions."}], "platforms": {"languages": ["Not Language-Specific"]}}, "357": {"name": "Insufficient UI Warning of Dangerous Operations", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The user interface provides a warning to a user regarding dangerous or sensitive operations, but the warning is not noticeable enough to warrant attention.", "consequences": [{"scope": ["Non-Repudiation"], "impact": ["Hide Activities"]}], "observed_examples": [{"cve": "CVE-2007-1099", "description": "User not sufficiently warned if host key mismatch occurs"}], "platforms": {"languages": ["Not Language-Specific"]}}, "358": {"name": "Improperly Implemented Security Check for Standard", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "observed_examples": [{"cve": "CVE-2002-0862", "description": "Browser does not verify Basic Constraints of a certificate, even though it is required, allowing spoofing of trusted certificates."}, {"cve": "CVE-2002-0970", "description": "Browser does not verify Basic Constraints of a certificate, even though it is required, allowing spoofing of trusted certificates."}, {"cve": "CVE-2002-1407", "description": "Browser does not verify Basic Constraints of a certificate, even though it is required, allowing spoofing of trusted certificates."}, {"cve": "CVE-2005-0198", "description": "Logic error prevents some required conditions from being enforced during Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5)."}, {"cve": "CVE-2004-2163", "description": "Shared secret not verified in a RADIUS response packet, allowing authentication bypass by spoofing server replies."}], "platforms": {"languages": ["Not Language-Specific"]}}, "359": {"name": "Exposure of Private Personal Information to an Unauthorized Actor", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "detection_methods": [{"method": "Architecture or Design Review"}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Static Analysis", "description": "Tools are available to analyze documents\n\t     (such as PDF, Word, etc.) to look for private information\n\t     such as names, addresses, etc."}], "observed_examples": [{"cve": "CVE-2023-29850", "description": "Library management product does not strip Exif data from images"}, {"cve": "CVE-2020-26220", "description": "Customer relationship management (CRM) product does not strip Exif data from images"}, {"cve": "CVE-2005-0406", "description": "Some image editors modify a JPEG image, but the original EXIF thumbnail image is left intact within the JPEG. (Also an interaction error)."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Mobile"]}}, "36": {"name": "Absolute Path Traversal", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as \"/abs/path\" that can resolve to a location that is outside of that directory.", "extended_description": "This allows attackers to traverse the file system to access files or directories that are outside of the restricted directory.", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Integrity"], "impact": ["Modify Files or Directories"]}, {"scope": ["Confidentiality"], "impact": ["Read Files or Directories"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}, {"description": "Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide d...", "phase": ["Operation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2024-0520", "description": "Product for managing datasets for AI model training and evaluation allows both relative (CWE-23) and absolute (CWE-36) path traversal to overwrite fil..."}, {"cve": "CVE-2022-31503", "description": "Python package constructs filenames using an unsafe os.path.join call on untrusted input, allowing absolute path traversal because os.path.join resets..."}, {"cve": "CVE-2002-1345", "description": "Multiple FTP clients write arbitrary files via absolute paths in server responses"}, {"cve": "CVE-2001-1269", "description": "ZIP file extractor allows full path"}, {"cve": "CVE-2002-1818", "description": "Path traversal using absolute pathname"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based", "AI/ML"]}}, "360": {"name": "Trust of System Event Data", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Security based on event locations are insecure and can be spoofed.", "extended_description": "Events are a messaging system which may provide control data to programs listening for events. Events often do not have any type of authentication framework to allow them to be verified from a trusted source. Any application, in Windows, on a given desktop can send a message to any window on the same desktop. There is no authentication framework for these messages. Therefore, any message can be used to manipulate any process on the desktop if the process does not check the validity and safeness ...", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability", "Access Control"], "impact": ["Gain Privileges or Assume Identity", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Never trust or rely any of the information in an Event for security.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2004-0213", "description": "Attacker uses Shatter attack to bypass GUI-enforced protection for CVE-2003-0908."}], "platforms": {"languages": ["Not Language-Specific"]}}, "362": {"name": "Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Resource Consumption (Other)"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart", "DoS: Instability"]}, {"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Read Application Data"]}, {"scope": ["Access Control"], "impact": ["Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "In languages that support it, use synchronization primitives. Only wrap these around critical code to minimize the impact on performance.", "phase": ["Architecture and Design"]}, {"description": "Use thread-safe capabilities such as the data access abstraction in Spring.", "phase": ["Architecture and Design"]}, {"description": "When using multithreading and operating on shared variables, only use thread-safe functions.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Black Box", "description": "Black box methods may be able to identify evidence of race conditions via methods such as multiple simultaneous connections, which may cause the software to become instable or crash. However, race con..."}, {"method": "White Box", "description": "Common idioms are detectable in white box analysis, such as time-of-check-time-of-use (TOCTOU) file operations (CWE-367), or double-checked locking (CWE-609)."}, {"method": "Automated Dynamic Analysis"}], "observed_examples": [{"cve": "CVE-2022-29527", "description": "Go application for cloud management creates a world-writable sudoers file that allows local attackers to inject sudo rules and escalate privileges to ..."}, {"cve": "CVE-2021-1782", "description": "Chain: improper locking (CWE-667) leads to race condition (CWE-362), as exploited in the wild per CISA KEV."}, {"cve": "CVE-2021-0920", "description": "Chain: mobile platform race condition (CWE-362) leading to use-after-free (CWE-416), as exploited in the wild per CISA KEV."}, {"cve": "CVE-2020-6819", "description": "Chain: race condition (CWE-362) leads to use-after-free (CWE-416), as exploited in the wild per CISA KEV."}, {"cve": "CVE-2019-18827", "description": "chain: JTAG interface is not disabled (CWE-1191) during ROM code execution, introducing a race condition (CWE-362) to extract encryption keys"}], "platforms": {"languages": ["C", "C++", "Java"], "technologies": ["Mobile", "ICS/OT"]}}, "363": {"name": "Race Condition Enabling Link Following", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product checks the status of a file or directory before accessing it, which produces a race condition in which the file can be replaced with a link before the access is performed, causing the product to access the wrong file.", "extended_description": "While developers might expect that there is a very narrow time window between the time of check and time of use, there is still a race condition. An attacker could cause the product to slow down (e.g. with memory consumption), causing the time window to become larger. Alternately, in some situations, the attacker could win the race by performing a large number of attacks.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "364": {"name": "Signal Handler Race Condition", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a signal handler that introduces a race condition.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Modify Application Data", "Modify Memory", "DoS: Crash, Exit, or Restart", "Execute Unauthorized Code or Commands"]}, {"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Use a language that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.", "phase": ["Requirements"]}, {"description": "Design signal handlers to only set flags, rather than perform complex functionality. These flags can then be checked and acted upon within the main program loop.", "phase": ["Architecture and Design"]}, {"description": "Only use reentrant functions within signal handlers. Also, use validation to ensure that state is consistent while performing asynchronous actions that affect the state of execution.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-1999-0035", "description": "Signal handler does not disable other signal handlers, allowing it to be interrupted, causing other functionality to access files/etc. with raised pri..."}, {"cve": "CVE-2001-0905", "description": "Attacker can send a signal while another signal handler is already running, leading to crash or execution with root privileges"}, {"cve": "CVE-2001-1349", "description": "unsafe calls to library functions from signal handler"}, {"cve": "CVE-2004-0794", "description": "SIGURG can be used to remotely interrupt signal handler; other variants exist"}, {"cve": "CVE-2004-2259", "description": "SIGCHLD signal to FTP server can cause crash under heavy load while executing non-reentrant functions like malloc/free."}], "platforms": {"languages": ["C", "C++"]}}, "365": {"name": "DEPRECATED: Race Condition in Switch", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "This entry has been deprecated. There are no documented cases in which a switch's control expression is evaluated more than once.", "extended_description": "It is likely that this entry was initially created based on a misinterpretation of the original source material. The original source intended to explain how switches could be unpredictable when using threads, if the control expressions used data or variables that could change between execution of different threads. That weakness is already covered by CWE-367. Despite the ambiguity in the documentation for some languages and compilers, in practice, they all evaluate the switch control expression ..."}, "366": {"name": "Race Condition within a Thread", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "If two threads of execution use a resource simultaneously, there exists the possibility that resources may be used while invalid, in turn making the state of execution undefined.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Alter Execution Logic", "Unexpected State"]}], "mitigations": [{"description": "Use locking functionality. This is the recommended solution. Implement some form of locking mechanism around code which alters or reads persistent data in a multithreaded environment.", "phase": ["Architecture and Design"]}, {"description": "Create resource-locking validation checks. If no inherent locking mechanisms exist, use flags and signals to enforce your own blocking scheme when resources are being used by other threads of execution.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-2621", "description": "Chain: two threads in a web browser use the same resource (CWE-366), but one of those threads can destroy the resource before the other has completed ..."}], "platforms": {"languages": ["C", "C++", "Java", "C#"], "technologies": ["Not Technology-Specific"]}}, "367": {"name": "Time-of-check Time-of-use (TOCTOU) Race Condition", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Alter Execution Logic", "Unexpected State"]}, {"scope": ["Integrity", "Other"], "impact": ["Modify Application Data", "Modify Files or Directories", "Modify Memory", "Other"]}, {"scope": ["Integrity", "Other"], "impact": ["Other"]}, {"scope": ["Non-Repudiation"], "impact": ["Hide Activities"]}, {"scope": ["Non-Repudiation", "Other"], "impact": ["Other"]}, {"scope": ["Other"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "The most basic advice for TOCTOU vulnerabilities is to not perform a check before the use. This does not resolve the underlying issue of the execution of a function on a resource whose state and identity cannot be assured, but it does help to limit the false sense of security given by the check.", "phase": ["Implementation"]}, {"description": "When the file being altered is owned by the current user and group, set the effective gid and uid to that of the current user and group when executing this statement.", "phase": ["Implementation"]}, {"description": "Limit the interleaving of operations on files from multiple processes.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2015-1743", "description": "TOCTOU in sandbox process allows installation of untrusted browser add-ons by replacing a file after it has been verified, but before it is executed"}, {"cve": "CVE-2003-0813", "description": "Chain: A multi-threaded race condition (CWE-367) allows attackers to cause two threads to process the same RPC request, which causes a use-after-free ..."}, {"cve": "CVE-2004-0594", "description": "PHP flaw allows remote attackers to execute arbitrary code by aborting execution before the initialization of key data structures is complete."}, {"cve": "CVE-2008-2958", "description": "chain: time-of-check time-of-use (TOCTOU) race condition in program allows bypass of protection mechanism that was designed to prevent symlink attacks..."}, {"cve": "CVE-2008-1570", "description": "chain: time-of-check time-of-use (TOCTOU) race condition in program allows bypass of protection mechanism that was designed to prevent symlink attacks..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "368": {"name": "Context Switching Race Condition", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A product performs a series of non-atomic actions to switch between contexts that cross privilege or other security boundaries, but a race condition allows an attacker to modify or misrepresent the product's behavior during the switch.", "extended_description": "This is commonly seen in web browser vulnerabilities in which the attacker can perform certain actions while the browser is transitioning from a trusted to an untrusted domain, or vice versa, and the browser performs the actions on one domain using the trust level and resources of the other domain.", "consequences": [{"scope": ["Integrity", "Confidentiality"], "impact": ["Modify Application Data", "Read Application Data"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2009-1837", "description": "Chain: race condition (CWE-362) from improper handling of a page transition in web client while an applet is loading (CWE-368) leads to use after free..."}, {"cve": "CVE-2004-2260", "description": "Browser updates address bar as soon as user clicks on a link instead of when the page has loaded, allowing spoofing by redirecting to another page usi..."}, {"cve": "CVE-2004-0191", "description": "XSS when web browser executes Javascript events in the context of a new page while it's being loaded, allowing interaction with previous page in diffe..."}, {"cve": "CVE-2004-2491", "description": "Web browser fills in address bar of clicked-on link before page has been loaded, and doesn't update afterward."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "369": {"name": "Divide By Zero", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product divides a value by zero.", "extended_description": "This weakness typically occurs when an unexpected value is provided to the product, or if an error occurs that is not properly detected. It frequently occurs in calculations involving physical dimensions such as size, length, width, and height.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}], "observed_examples": [{"cve": "CVE-2007-3268", "description": "Invalid size value leads to divide by zero."}, {"cve": "CVE-2007-2723", "description": "\"Empty\" content triggers divide by zero."}, {"cve": "CVE-2007-2237", "description": "Height value of 0 triggers divide by zero."}], "platforms": {"languages": ["Not Language-Specific"]}}, "37": {"name": "Path Traversal: '/absolute/pathname/here'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts input in the form of a slash absolute path ('/absolute/pathname/here') without appropriate validation, which can allow an attacker to traverse the file system to unintended locations or access arbitrary files.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2002-1345", "description": "Multiple FTP clients write arbitrary files via absolute paths in server responses"}, {"cve": "CVE-2001-1269", "description": "ZIP file extractor allows full path"}, {"cve": "CVE-2002-1818", "description": "Path traversal using absolute pathname"}, {"cve": "CVE-2002-1913", "description": "Path traversal using absolute pathname"}, {"cve": "CVE-2005-2147", "description": "Path traversal using absolute pathname"}], "platforms": {"languages": ["Not Language-Specific"]}}, "370": {"name": "Missing Check for Certificate Revocation after Initial Check", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not check the revocation status of a certificate after its initial revocation check, which can cause the product to perform privileged actions even after the certificate is revoked at a later time.", "extended_description": "If the revocation status of a certificate is not checked before each action that requires privileges, the system may be subject to a race condition. If a certificate is revoked after the initial check, all subsequent actions taken with the owner of the revoked certificate will lose all benefits guaranteed by the certificate. In fact, it is almost certain that the use of a revoked certificate indicates malicious activity.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Integrity"], "impact": ["Modify Application Data"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Ensure that certificates are checked for revoked status before each use of a protected resource. If the certificate is checked before each access of a protected resource, the delay subject to a possible race condition becomes almost negligible and significantly reduces the risk associated with this ...", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "372": {"name": "Incomplete Internal State Distinction", "abstraction": "Base", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not properly determine which state it is in, causing it to assume it is in state X when in fact it is in state Y, causing it to perform incorrect operations in a security-relevant manner.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Varies by Context", "Unexpected State"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "373": {"name": "DEPRECATED: State Synchronization Error", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "This entry was deprecated because it overlapped the same concepts as race condition (CWE-362) and Improper Synchronization (CWE-662)."}, "374": {"name": "Passing Mutable Objects to an Untrusted Method", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product sends non-cloned mutable data as an argument to a method or function.", "extended_description": "The function or method that has been called can alter or delete the mutable data. This could violate assumptions that the calling function has made about its state. In situations where unknown code is called with references to mutable data, this external code could make changes to the data sent. If this data was not previously cloned, the modified data might not be valid in the context of execution.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Memory"]}], "mitigations": [{"description": "Pass in data which should not be altered as constant or immutable.", "phase": ["Implementation"]}, {"description": "Clone all mutable data before passing it into an external function . This is the preferred mitigation. This way, regardless of what changes are made to the data, a valid copy is retained for use by the class.", "phase": ["Implementation"]}], "platforms": {"languages": ["Object-Oriented", "C", "C++", "Java", "C#"]}}, "375": {"name": "Returning a Mutable Object to an Untrusted Caller", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Sending non-cloned mutable data as a return value may result in that data being altered or deleted by the calling function.", "extended_description": "In situations where functions return references to mutable data, it is possible that the external code which called the function may make changes to the data sent. If this data was not previously cloned, the class will then be using modified data which may violate assumptions about its internal state.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Access Control", "Integrity"], "impact": ["Modify Memory"]}], "mitigations": [{"description": "Declare returned data which should not be altered as constant or immutable.", "phase": ["Implementation"]}, {"description": "Clone all mutable data before returning references to it. This is the preferred mitigation. This way, regardless of what changes are made to the data, a valid copy is retained for use by the class.", "phase": ["Implementation"]}], "platforms": {"languages": ["Object-Oriented", "C", "C++", "Java", "C#"]}}, "377": {"name": "Insecure Temporary File", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "Creating and using insecure temporary files can leave application and system data vulnerable to attack.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-41954", "description": "A library uses the Java File.createTempFile() method which creates a file with \"-rw-r--r--\" default permissions on Unix-like operating systems"}], "platforms": {"languages": ["Not Language-Specific"]}}, "378": {"name": "Creation of Temporary File With Insecure Permissions", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Opening temporary files without appropriate measures or controls can leave the file, its contents and any function that it impacts vulnerable to attack.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Authorization", "Other"], "impact": ["Other"]}, {"scope": ["Integrity", "Other"], "impact": ["Other"]}], "mitigations": [{"description": "Many contemporary languages have functions which properly handle this condition. Older C temp file functions are especially susceptible.", "phase": ["Requirements"]}, {"description": "Ensure that you use proper file permissions. This can be achieved by using a safe temp file function. Temporary files should be writable and readable only by the process that owns the file.", "phase": ["Implementation"]}, {"description": "Randomize temporary file names. This can also be achieved by using a safe temp-file function. This will ensure that temporary files will not be created in predictable places.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-24823", "description": "A network application framework uses the Java function createTempFile(), which will create a file that is readable by other local users of the system"}], "platforms": {"languages": ["Not Language-Specific"]}}, "379": {"name": "Creation of Temporary File in Directory with Insecure Permissions", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product creates a temporary file in a directory whose permissions allow unintended actors to determine the file's existence or otherwise access that file.", "extended_description": "On some operating systems, the fact that the temporary file exists may be apparent to any user with sufficient privileges to access that directory. Since the file is visible, the application that is using the temporary file could be known. If one has access to list the processes on the system, the attacker has gained information about what the user is doing at that time. By correlating this with the applications the user is running, an attacker could potentially discover what a user's actions ar...", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Many contemporary languages have functions which properly handle this condition. Older C temp file functions are especially susceptible.", "phase": ["Requirements"]}, {"description": "Try to store sensitive tempfiles in a directory which is not world readable -- i.e., per-user directories.", "phase": ["Implementation"]}, {"description": "Avoid using vulnerable temp file functions.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-27818", "description": "A hotkey daemon written in Rust creates a domain socket file underneath /tmp, which is accessible by any user."}, {"cve": "CVE-2021-21290", "description": "A Java-based application for a rapid-development framework uses File.createTempFile() to create a random temporary file with insecure default permissi..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "38": {"name": "Path Traversal: '\\absolute\\pathname\\here'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts input in the form of a backslash absolute path ('\\absolute\\pathname\\here') without appropriate validation, which can allow an attacker to traverse the file system to unintended locations or access arbitrary files.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-1999-1263", "description": "Mail client allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathn..."}, {"cve": "CVE-2003-0753", "description": "Remote attackers can read arbitrary files via a full pathname to the target file in config parameter."}, {"cve": "CVE-2002-1525", "description": "Remote attackers can read arbitrary files via an absolute pathname."}], "platforms": {"languages": ["Not Language-Specific"]}}, "382": {"name": "J2EE Bad Practices: Use of System.exit()", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "A J2EE application uses System.exit(), which also shuts down its container.", "extended_description": "It is never a good idea for a web application to attempt to shut down the application container. Access to a function that can shut down the application is an avenue for Denial of Service (DoS) attacks.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "The shutdown function should be a privileged function available only to a properly authorized administrative user", "phase": ["Architecture and Design"]}, {"description": "Web applications should not call methods that cause the virtual machine to exit, such as System.exit()", "phase": ["Implementation"]}, {"description": "Web applications should also not throw any Throwables to the application server as this may adversely affect the container.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"], "technologies": ["Web Based", "Web Server"]}}, "383": {"name": "J2EE Bad Practices: Direct Use of Threads", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Thread management in a Web application is forbidden in some circumstances and is always highly error prone.", "extended_description": "Thread management in a web application is forbidden by the J2EE standard in some circumstances and is always highly error prone. Managing threads is difficult and is likely to interfere in unpredictable ways with the behavior of the application container. Even without interfering with the container, thread management usually leads to bugs that are hard to detect and diagnose like deadlock, race conditions, and other synchronization errors.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "mitigations": [{"description": "For EJB, use framework approaches for parallel execution, instead of using threads.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"], "technologies": ["Web Based", "Web Server"]}}, "384": {"name": "Session Fixation", "abstraction": "Compound", "mapping": "ALLOWED", "structure": "Composite", "description": "Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Invalidate any existing session identifiers prior to authorizing a new user session.", "phase": ["Architecture and Design"]}, {"description": "For platforms such as ASP that do not generate new values for sessionid cookies, utilize a secondary cookie. In this approach, set a secondary cookie on the user's browser to a random value and set a session variable to the same value. If the session variable and the cookie value ever don't match, i...", "phase": ["Architecture and Design"]}, {"description": "Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide d...", "phase": ["Operation"]}], "observed_examples": [{"cve": "CVE-2022-2820", "description": "Website software for game servers does not proprerly terminate user sessions, allowing for possible session fixation"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "385": {"name": "Covert Timing Channel", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Covert timing channels convey information by modulating some aspect of system behavior over time, so that the program receiving the information can observe system behavior and infer protected information.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality", "Other"], "impact": ["Read Application Data", "Other"]}], "mitigations": [{"description": "Whenever possible, specify implementation strategies that do not introduce time variances in operations.", "phase": ["Architecture and Design"]}, {"description": "Often one can artificially manipulate the time which operations take or -- when operations occur -- can remove information from the attacker.", "phase": ["Implementation"]}, {"description": "It is reasonable to add artificial or random delays so that the amount of CPU time consumed is independent of the action being taken by the application.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "386": {"name": "Symbolic Name not Mapping to Correct Object", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A constant symbolic reference to an object is used, even though the reference can resolve to a different object over time.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Integrity", "Confidentiality", "Other"], "impact": ["Modify Application Data", "Modify Files or Directories", "Read Application Data", "Read Files or Directories", "Other"]}, {"scope": ["Integrity", "Other"], "impact": ["Modify Application Data", "Other"]}, {"scope": ["Non-Repudiation"], "impact": ["Hide Activities"]}, {"scope": ["Non-Repudiation", "Integrity"], "impact": ["Modify Files or Directories"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "39": {"name": "Path Traversal: 'C:dirname'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts input that contains a drive letter or Windows volume letter ('C:dirname') that potentially redirects access to an unintended location or arbitrary file.", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Integrity"], "impact": ["Modify Files or Directories"]}, {"scope": ["Confidentiality"], "impact": ["Read Files or Directories"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2001-0038", "description": "Remote attackers can read arbitrary files by specifying the drive letter in the requested URL."}, {"cve": "CVE-2001-0255", "description": "FTP server allows remote attackers to list arbitrary directories by using the \"ls\" command and including the drive letter name (e.g. C:) in the reques..."}, {"cve": "CVE-2001-0687", "description": "FTP server allows a remote attacker to retrieve privileged system information by specifying arbitrary paths."}, {"cve": "CVE-2001-0933", "description": "FTP server allows remote attackers to list the contents of arbitrary drives via a ls command that includes the drive letter as an argument."}, {"cve": "CVE-2002-0466", "description": "Server allows remote attackers to browse arbitrary directories via a full pathname in the arguments to certain dynamic pages."}], "platforms": {"languages": ["Not Language-Specific"]}}, "390": {"name": "Detection of Error Condition Without Action", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product detects a specific error, but takes no actions to handle the error.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Varies by Context", "Unexpected State", "Alter Execution Logic"]}], "mitigations": [{"description": "Properly handle each exception. This is the recommended solution. Ensure that all exceptions are handled in such a way that you can be sure of the state of your system at any given moment.", "phase": ["Implementation"]}, {"description": "If a function returns an error, it is important to either fix the problem and try again, alert the user that an error has happened and let the program continue, or alert the user and close and cleanup the program.", "phase": ["Implementation"]}, {"description": "Subject the product to extensive testing to discover some of the possible instances of where/how errors or return values are not handled. Consider testing techniques such as ad hoc, equivalence partitioning, robustness and fault tolerance, mutation, and fuzzing.", "phase": ["Testing"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-21820", "description": "A GPU data center manager detects an error due to a malformed request but does not act on it, leading to memory corruption."}], "platforms": {"languages": ["Not Language-Specific"]}}, "391": {"name": "Unchecked Error Condition", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "[PLANNED FOR DEPRECATION. SEE MAINTENANCE NOTES AND CONSIDER CWE-252, CWE-248, OR CWE-1069.] Ignoring exceptions and other error conditions may allow an attacker to induce unexpected behavior unnoticed.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Varies by Context", "Unexpected State", "Alter Execution Logic"]}], "mitigations": [{"description": "The choice between a language which has named or unnamed exceptions needs to be done. While unnamed exceptions exacerbate the chance of not properly dealing with an exception, named exceptions suffer from the up call version of the weak base class problem.", "phase": ["Requirements"]}, {"description": "A language can be used which requires, at compile time, to catch all serious exceptions. However, one must make sure to use the most current version of the API as new exceptions could be added.", "phase": ["Requirements"]}, {"description": "Catch all relevant exceptions. This is the recommended solution. Ensure that all exceptions are handled in such a way that you can be sure of the state of your system at any given moment.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "392": {"name": "Missing Report of Error Condition", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product encounters an error but does not provide a status code or return value to indicate that an error has occurred.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Varies by Context", "Unexpected State"]}], "observed_examples": [{"cve": "[REF-1374]", "description": "Chain: JavaScript-based cryptocurrency library can fall back to the insecure Math.random() function instead of reporting a failure (CWE-392), thus red..."}, {"cve": "CVE-2004-0063", "description": "Function returns \"OK\" even if another function returns a different status code than expected, leading to accepting an invalid PIN number."}, {"cve": "CVE-2002-1446", "description": "Error checking routine in PKCS#11 library returns \"OK\" status even when invalid signature is detected, allowing spoofed messages."}, {"cve": "CVE-2002-0499", "description": "Kernel function truncates long pathnames without generating an error, leading to operation on wrong directory."}, {"cve": "CVE-2005-2459", "description": "Function returns non-error value when a particular erroneous condition is encountered, leading to resultant NULL dereference."}], "platforms": {"languages": ["Not Language-Specific"]}}, "393": {"name": "Return of Wrong Status Code", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A function or operation returns an incorrect return value or status code that does not indicate the true result of execution, causing the product to modify its behavior based on the incorrect result.", "extended_description": "This can lead to unpredictable behavior. If the function is used to make security-critical decisions or provide security-critical information, then the wrong status code can cause the product to assume that an action is safe or correct, even when it is not.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Unexpected State", "Alter Execution Logic"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}], "observed_examples": [{"cve": "CVE-2003-1132", "description": "DNS server returns wrong response code for non-existent AAAA record, which effectively says that the domain is inaccessible."}, {"cve": "CVE-2001-1509", "description": "Hardware-specific implementation of system call causes incorrect results from geteuid."}, {"cve": "CVE-2001-1559", "description": "Chain: System call returns wrong value (CWE-393), leading to a resultant NULL dereference (CWE-476)."}, {"cve": "CVE-2014-1266", "description": "Chain: incorrect \"goto\" in Apple SSL product bypasses certificate validation, allowing Adversary-in-the-Middle (AITM) attack (Apple \"goto fail\" bug). ..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "394": {"name": "Unexpected Status Code or Return Value", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly check when a function or operation returns a value that is legitimate for the function, but is not expected by the product.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Unexpected State", "Alter Execution Logic"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2004-1395", "description": "Certain packets (zero byte and other lengths) cause a recvfrom call to produce an unexpected return code that causes a server's listening loop to exit..."}, {"cve": "CVE-2002-2124", "description": "Unchecked return code from recv() leads to infinite loop."}, {"cve": "CVE-2005-2553", "description": "Kernel function does not properly handle when a null is returned by a function call, causing it to call another function that it shouldn't."}, {"cve": "CVE-2005-1858", "description": "Memory not properly cleared when read() function call returns fewer bytes than expected."}, {"cve": "CVE-2000-0536", "description": "Bypass access restrictions when connecting from IP whose DNS reverse lookup does not return a hostname."}], "platforms": {"languages": ["Not Language-Specific"]}}, "395": {"name": "Use of NullPointerException Catch to Detect NULL Pointer Dereference", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Catching NullPointerException should not be used as an alternative to programmatic checks to prevent dereferencing a null pointer.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)"]}], "mitigations": [{"description": "Do not extensively rely on catching exceptions (especially for validating user input) to handle errors. Handling exceptions can decrease the performance of an application.", "phase": ["Architecture and Design", "Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Dynamic Analysis with Manual Results Interpretation"}, {"method": "Manual Static Analysis - Source Code"}], "platforms": {"languages": ["Java"]}}, "396": {"name": "Declaration of Catch for Generic Exception", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Catching overly broad exceptions promotes complex error handling code that is more likely to contain security vulnerabilities.", "extended_description": "Multiple catch blocks can get ugly and repetitive, but \"condensing\" catch blocks by catching a high-level class like Exception can obscure exceptions that deserve special treatment or that should not be caught at this point in the program. Catching an overly broad exception essentially defeats the purpose of a language's typed exceptions, and can become particularly dangerous if the program grows and begins to throw new types of exceptions. The new exception types will not receive any attention.", "consequences": [{"scope": ["Non-Repudiation", "Other"], "impact": ["Hide Activities"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C++", "Java", "C#", "Python"]}}, "397": {"name": "Declaration of Throws for Generic Exception", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product throws or raises an overly broad exceptions that can hide important details and produce inappropriate responses to certain conditions.", "extended_description": "Declaring a method to throw Exception or Throwable promotes generic error handling procedures that make it difficult for callers to perform proper error handling and error recovery. For example, Java's exception mechanism makes it easy for callers to anticipate what can go wrong and write code to handle each specific exceptional circumstance. Declaring that a method throws a generic form of exception defeats this system.", "consequences": [{"scope": ["Non-Repudiation", "Other"], "impact": ["Hide Activities", "Alter Execution Logic"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C++", "C#", "Java", "Python"]}}, "40": {"name": "Path Traversal: '\\\\UNC\\share\\name\\' (Windows UNC Share)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts input that identifies a Windows UNC share ('\\\\UNC\\share\\name') that potentially redirects access to an unintended location or arbitrary file.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2001-0687", "description": "FTP server allows a remote attacker to retrieve privileged web server system information by specifying arbitrary paths in the UNC format (\\\\computerna..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "400": {"name": "Uncontrolled Resource Consumption", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not properly control the allocation and maintenance of a limited resource.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Resource Consumption (Other)"]}, {"scope": ["Access Control", "Other"], "impact": ["Bypass Protection Mechanism", "Other"]}], "mitigations": [{"description": "Design throttling mechanisms into the system architecture. The best protection is to limit the amount of resources that an unauthorized user can cause to be expended. A strong authentication and access control model will help prevent such attacks from occurring in the first place. The login applicat...", "phase": ["Architecture and Design"]}, {"description": "Ensure that protocols have specific limits of scale placed on them.", "phase": ["Architecture and Design"]}, {"description": "Ensure that all failures in resource allocation place the system into a safe posture.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis"}, {"method": "Automated Dynamic Analysis", "description": "Certain automated dynamic analysis techniques may be effective in spotting resource exhaustion problems, especially with resources such as processes, memory, and connections. The technique may involve..."}, {"method": "Fuzzing", "description": "While fuzzing is typically geared toward finding low-level implementation bugs, it can inadvertently find resource exhaustion problems. This can occur when the fuzzer generates a large number of test ..."}], "observed_examples": [{"cve": "CVE-2019-19911", "description": "Chain: Python library does not limit the resources used to process images that specify a very large number of bands (CWE-1284), leading to excessive m..."}, {"cve": "CVE-2020-7218", "description": "Go-based workload orchestrator does not limit resource usage with unauthenticated connections, allowing a DoS by flooding the service"}, {"cve": "CVE-2020-3566", "description": "Resource exhaustion in distributed OS because of \"insufficient\" IGMP queue management, as exploited in the wild per CISA KEV."}, {"cve": "CVE-2009-2874", "description": "Product allows attackers to cause a crash via a large number of connections."}, {"cve": "CVE-2009-1928", "description": "Malformed request triggers uncontrolled recursion, leading to stack exhaustion."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "401": {"name": "Missing Release of Memory after Effective Lifetime", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart", "DoS: Instability", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)"]}, {"scope": ["Other"], "impact": ["Reduce Performance"]}], "mitigations": [{"description": "Use an abstraction library to abstract away risky APIs. Not a complete solution.", "phase": ["Architecture and Design"]}, {"description": "The Boehm-Demers-Weiser Garbage Collector or valgrind can be used to detect leaks in code.", "phase": ["Architecture and Design", "Build and Compilation"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2005-3119", "description": "Memory leak because function does not free() an element of a data structure."}, {"cve": "CVE-2004-0427", "description": "Memory leak when counter variable is not decremented."}, {"cve": "CVE-2002-0574", "description": "chain: reference count is not decremented, leading to memory leak in OS by sending ICMP packets."}, {"cve": "CVE-2005-3181", "description": "Kernel uses wrong function to release a data structure, preventing data from being properly tracked by other code."}, {"cve": "CVE-2004-0222", "description": "Memory leak via unknown manipulations as part of protocol test suite."}], "platforms": {"languages": ["Not Language-Specific", "C", "C++"]}}, "402": {"name": "Transmission of Private Resources into a New Sphere ('Resource Leak')", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2003-0740", "description": "Server leaks a privileged file descriptor, allowing the server to be hijacked."}, {"cve": "CVE-2004-1033", "description": "File descriptor leak allows read of restricted files."}], "platforms": {"languages": ["Not Language-Specific"]}}, "403": {"name": "Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A process does not close sensitive file descriptors before invoking a child process, which allows the child to perform unauthorized I/O operations using those descriptors.", "extended_description": "When a new process is forked or executed, the child process inherits any open file descriptors. When the child process has fewer privileges than the parent process, this might introduce a vulnerability if the child process can access the file descriptor but does not have the privileges to access the associated file.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2003-0740", "description": "Server leaks a privileged file descriptor, allowing the server to be hijacked."}, {"cve": "CVE-2004-1033", "description": "File descriptor leak allows read of restricted files."}, {"cve": "CVE-2000-0094", "description": "Access to restricted resource using modified file descriptor for stderr."}, {"cve": "CVE-2002-0638", "description": "Open file descriptor used as alternate channel in complex race condition."}, {"cve": "CVE-2003-0489", "description": "Program does not fully drop privileges after creating a file descriptor, which allows access to the descriptor via a separate vulnerability."}], "platforms": {"languages": ["C", "Not Language-Specific"]}}, "404": {"name": "Improper Resource Shutdown or Release", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not release or incorrectly releases a resource before it is made available for re-use.", "extended_description": "When a resource is created or allocated, the developer is responsible for properly releasing the resource as well as accounting for all potential paths of expiration or invalidation, such as a set period of time or revocation.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Availability", "Other"], "impact": ["DoS: Resource Consumption (Other)", "Varies by Context"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "It is good practice to be responsible for freeing all resources you allocate and to be consistent with how and where you free memory in a function. If you allocate memory that you intend to free upon completion of the function, you must be sure to free the memory at all exit points for that function...", "phase": ["Implementation"]}, {"description": "Memory should be allocated/freed using matching functions such as malloc/free, new/delete, and new[]/delete[].", "phase": ["Implementation"]}, {"description": "When releasing a complex object or structure, ensure that you properly dispose of all of its member components, not just the object itself.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Dynamic Analysis"}, {"method": "Manual Dynamic Analysis", "description": "Identify error conditions that are not likely to occur during normal usage and trigger them. For example, run the product under low memory conditions, run with insufficient privileges or permissions, ..."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-1999-1127", "description": "Does not shut down named pipe connections if malformed data is sent."}, {"cve": "CVE-2001-0830", "description": "Sockets not properly closed when attacker repeatedly connects and disconnects from server."}, {"cve": "CVE-2002-1372", "description": "Chain: Return values of file/socket operations are not checked (CWE-252), allowing resultant consumption of file descriptors (CWE-772)."}], "platforms": {"languages": ["Not Language-Specific"]}}, "405": {"name": "Asymmetric Resource Consumption (Amplification)", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is \"asymmetric.\"", "extended_description": "This can lead to poor performance due to \"amplification\" of resource consumption, typically in a non-linear fashion.  This situation is worsened if the product allows malicious users or attackers to consume more resources than their access level permits.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Amplification", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Resource Consumption (Other)"]}], "mitigations": [{"description": "An application must make resources available to a client commensurate with the client's access level.", "phase": ["Architecture and Design"]}, {"description": "An application must, at all times, keep track of allocated resources and meter their usage appropriately.", "phase": ["Architecture and Design"]}, {"description": "Consider disabling resource-intensive algorithms on the server side, such as Diffie-Hellman key exchange.", "phase": ["System Configuration"]}], "observed_examples": [{"cve": "CVE-1999-0513", "description": "Classic \"Smurf\" attack, using spoofed ICMP packets to broadcast addresses."}, {"cve": "CVE-2003-1564", "description": "Parsing library allows XML bomb"}, {"cve": "CVE-2004-2458", "description": "Tool creates directories before authenticating user."}, {"cve": "CVE-2020-10735", "description": "Python has \"quadratic complexity\" issue when converting string to int with many digits in unexpected bases"}, {"cve": "CVE-2020-5243", "description": "server allows ReDOS with crafted User-Agent strings, due to overlapping capture groups that cause excessive backtracking."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Client Server"]}}, "406": {"name": "Insufficient Control of Network Message Volume (Network Amplification)", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not sufficiently monitor or control transmitted network traffic volume, so that an actor can cause the product to transmit more traffic than should be allowed for that actor.", "extended_description": "In the absence of a policy to restrict asymmetric resource consumption, the application or system cannot distinguish between legitimate transmissions and traffic intended to serve as an amplifying attack on target systems. Systems can often be configured to restrict the amount of traffic sent out on behalf of a client, based on the client's origin or access level. This is usually defined in a resource allocation policy. In the absence of a mechanism to keep track of transmissions, the system or ...", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Amplification", "DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Resource Consumption (Other)"]}], "mitigations": [{"description": "An application must make network resources available to a client commensurate with the client's access level.", "phase": ["Architecture and Design"]}, {"description": "Define a clear policy for network resource allocation and consumption.", "phase": ["Policy"]}, {"description": "An application must, at all times, keep track of network resources and meter their usage appropriately.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-1999-0513", "description": "Classic \"Smurf\" attack, using spoofed ICMP packets to broadcast addresses."}, {"cve": "CVE-1999-1379", "description": "DNS query with spoofed source address causes more traffic to be returned to spoofed address than was sent by the attacker."}, {"cve": "CVE-2000-0041", "description": "Large datagrams are sent in response to malformed datagrams."}, {"cve": "CVE-1999-1066", "description": "Game server sends a large amount."}, {"cve": "CVE-2013-5211", "description": "composite: NTP feature generates large responses (high amplification factor) with spoofed UDP source addresses."}], "platforms": {"languages": ["Not Language-Specific"]}}, "407": {"name": "Inefficient Algorithmic Complexity", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Resource Consumption (Other)"]}], "observed_examples": [{"cve": "CVE-2021-32617", "description": "C++ library for image metadata has \"quadratic complexity\" issue with unnecessarily repetitive parsing each time an invalid character is encountered"}, {"cve": "CVE-2020-10735", "description": "Python has \"quadratic complexity\" issue when converting string to int with many digits in unexpected bases"}, {"cve": "CVE-2020-5243", "description": "server allows ReDOS with crafted User-Agent strings, due to overlapping capture groups that cause excessive backtracking."}, {"cve": "CVE-2014-1474", "description": "Perl-based email address parser has \"quadratic complexity\" issue via a string that does not contain a valid address"}, {"cve": "CVE-2003-0244", "description": "CPU consumption via inputs that cause many hash table collisions."}], "platforms": {"languages": ["Not Language-Specific"]}}, "408": {"name": "Incorrect Behavior Order: Early Amplification", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product allows an entity to perform a legitimate but expensive operation before authentication or authorization has taken place.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Amplification", "DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)"]}], "observed_examples": [{"cve": "CVE-2004-2458", "description": "Tool creates directories before authenticating user."}], "platforms": {"languages": ["Not Language-Specific"]}}, "409": {"name": "Improper Handling of Highly Compressed Data (Data Amplification)", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.", "extended_description": "An example of data amplification is a \"decompression bomb,\" a small ZIP file that can produce a large amount of data when it is decompressed.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Amplification", "DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)"]}], "observed_examples": [{"cve": "CVE-2009-1955", "description": "XML bomb in web server module"}, {"cve": "CVE-2003-1564", "description": "Parsing library allows XML bomb"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "41": {"name": "Improper Resolution of Path Equivalence", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product is vulnerable to file system contents disclosure through path equivalence. Path equivalence involves the use of special characters in file and directory names. The associated manipulations are intended to generate multiple names for the same object.", "extended_description": "Path equivalence is usually employed in order to circumvent access controls expressed using an incomplete set of file name or file path representations. This is different from path traversal, wherein the manipulations are performed to generate a name for a different object.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Access Control"], "impact": ["Read Files or Directories", "Modify Files or Directories", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Use and specify an output encoding that can be handled by the downstream component that is reading the output. Common encodings include ISO-8859-1, UTF-7, and UTF-8. When an encoding is not specified, a downstream component may choose a different encoding, either by assuming a default encoding or au...", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Manual Static Analysis - Binary or Bytecode"}, {"method": "Dynamic Analysis with Automated Results Interpretation"}], "observed_examples": [{"cve": "CVE-2000-1114", "description": "Source code disclosure using trailing dot"}, {"cve": "CVE-2002-1986", "description": "Source code disclosure using trailing dot"}, {"cve": "CVE-2004-2213", "description": "Source code disclosure using trailing dot or trailing encoding space \"%20\""}, {"cve": "CVE-2005-3293", "description": "Source code disclosure using trailing dot"}, {"cve": "CVE-2004-0061", "description": "Bypass directory access restrictions using trailing dot in URL"}], "platforms": {"languages": ["Not Language-Specific"]}}, "410": {"name": "Insufficient Resource Pool", "abstraction": "Class", "mapping": "ALLOWED", "structure": "Simple", "description": "The product's resource pool is not large enough to handle peak demand, which allows an attacker to prevent others from accessing the resource by using a (relatively) large number of requests for resources.", "extended_description": "Frequently the consequence is a \"flood\" of connection or sessions.", "consequences": [{"scope": ["Availability", "Integrity", "Other"], "impact": ["DoS: Crash, Exit, or Restart", "Other"]}], "mitigations": [{"description": "Do not perform resource-intensive transactions for unauthenticated users and/or invalid requests.", "phase": ["Architecture and Design"]}, {"description": "Consider implementing a velocity check mechanism which would detect abusive behavior.", "phase": ["Architecture and Design"]}, {"description": "Consider load balancing as an option to handle heavy loads.", "phase": ["Operation"]}], "observed_examples": [{"cve": "CVE-1999-1363", "description": "Large number of locks on file exhausts the pool and causes crash."}, {"cve": "CVE-2001-1340", "description": "Product supports only one connection and does not disconnect a user who does not provide credentials."}, {"cve": "CVE-2002-0406", "description": "Large number of connections without providing credentials allows connection exhaustion."}], "platforms": {"languages": ["Not Language-Specific"]}}, "412": {"name": "Unrestricted Externally Accessible Lock", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product properly checks for the existence of a lock, but the lock can be externally controlled or influenced by an actor that is outside of the intended sphere of control.", "extended_description": "This prevents the product from acting on associated resources or performing other behaviors that are controlled by the presence of the lock. Relevant locks might include an exclusive lock or mutex, or modifying a shared resource that is treated as a lock. If the lock can be held for an indefinite period of time, then the denial of service could be permanent.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (Other)"]}], "mitigations": [{"description": "Use any access control that is offered by the functionality that is offering the lock.", "phase": ["Architecture and Design", "Implementation"]}, {"description": "Use unpredictable names or identifiers for the locks. This might not always be possible or feasible.", "phase": ["Architecture and Design", "Implementation"]}, {"description": "Consider modifying your code to use non-blocking synchronization methods.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "White Box", "description": "Automated code analysis techniques might not be able to reliably detect this weakness, since the application's behavior and general security model dictate which resource locks are critical. Interpreta..."}], "observed_examples": [{"cve": "CVE-2001-0682", "description": "Program can not execute when attacker obtains a mutex."}, {"cve": "CVE-2002-1914", "description": "Program can not execute when attacker obtains a lock on a critical output file."}, {"cve": "CVE-2002-1915", "description": "Program can not execute when attacker obtains a lock on a critical output file."}, {"cve": "CVE-2002-0051", "description": "Critical file can be opened with exclusive read access by user, preventing application of security policy. Possibly related to improper permissions, l..."}, {"cve": "CVE-2000-0338", "description": "Chain: predictable file names used for locking, allowing attacker to create the lock beforehand. Resultant from permissions and randomness."}], "platforms": {"languages": ["Not Language-Specific"]}}, "413": {"name": "Improper Resource Locking", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not lock or does not correctly lock a resource when the product must have exclusive access to the resource.", "extended_description": "When a resource is not properly locked, an attacker could modify the resource while it is being operated on by the product. This might violate the product's assumption that the resource will not change, potentially leading to unexpected behaviors.", "consequences": [{"scope": ["Integrity", "Availability"], "impact": ["Modify Application Data", "DoS: Instability", "DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Use a non-conflicting privilege scheme.", "phase": ["Architecture and Design"]}, {"description": "Use synchronization when locking a resource.", "phase": ["Architecture and Design", "Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-20141", "description": "Chain: an operating system kernel has insufficent resource locking (CWE-413) leading to a use after free (CWE-416)."}], "platforms": {"languages": ["Not Language-Specific"]}}, "414": {"name": "Missing Lock Check", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A product does not check to see if a lock is present before performing sensitive operations on a resource.", "consequences": [{"scope": ["Integrity", "Availability"], "impact": ["Modify Application Data", "DoS: Instability", "DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Implement a reliable lock mechanism.", "phase": ["Architecture and Design", "Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2004-1056", "description": "Product does not properly check if a lock is present, allowing other attackers to access functionality."}], "platforms": {"languages": ["Not Language-Specific"]}}, "415": {"name": "Double Free", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product calls free() twice on the same memory address.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Modify Memory", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Choose a language that provides automatic memory management.", "phase": ["Architecture and Design"]}, {"description": "Ensure that each allocation is freed only once. After freeing a chunk, set the pointer to NULL to ensure the pointer cannot be freed again. In complicated error conditions, be sure that clean-up routines respect the state of allocation properly. If the language is object oriented, ensure that object...", "phase": ["Implementation"]}, {"description": "Use a static analysis tool to find double free instances.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2006-5051", "description": "Chain: Signal handler contains too much functionality (CWE-828), introducing a race condition (CWE-362) that leads to a double free (CWE-415)."}, {"cve": "CVE-2004-0642", "description": "Double free resultant from certain error conditions."}, {"cve": "CVE-2004-0772", "description": "Double free resultant from certain error conditions."}, {"cve": "CVE-2005-1689", "description": "Double free resultant from certain error conditions."}, {"cve": "CVE-2003-0545", "description": "Double free from invalid ASN.1 encoding."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "416": {"name": "Use After Free", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory \"belongs\" to the code that operates on the new pointer.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Memory"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Choose a language that provides automatic memory management.", "phase": ["Architecture and Design"]}, {"description": "When freeing pointers, be sure to set them to NULL once they are freed. However, the utilization of multiple or complex data structures may lower the usefulness of this strategy.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2022-20141", "description": "Chain: an operating system kernel has insufficent resource locking (CWE-413) leading to a use after free (CWE-416)."}, {"cve": "CVE-2022-2621", "description": "Chain: two threads in a web browser use the same resource (CWE-366), but one of those threads can destroy the resource before the other has completed ..."}, {"cve": "CVE-2021-0920", "description": "Chain: mobile platform race condition (CWE-362) leading to use-after-free (CWE-416), as exploited in the wild per CISA KEV."}, {"cve": "CVE-2020-6819", "description": "Chain: race condition (CWE-362) leads to use-after-free (CWE-416), as exploited in the wild per CISA KEV."}, {"cve": "CVE-2010-4168", "description": "Use-after-free triggered by closing a connection while data is still being transmitted."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "419": {"name": "Unprotected Primary Channel", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a primary channel for administration or restricted functionality, but it does not properly protect the channel.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Do not expose administrative functionnality on the user UI.", "phase": ["Architecture and Design"]}, {"description": "Protect the administrative/restricted functionality with a strong authentication mechanism.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "42": {"name": "Path Equivalence: 'filename.' (Trailing Dot)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts path input in the form of trailing dot ('filedir.') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "observed_examples": [{"cve": "CVE-2000-1114", "description": "Source code disclosure using trailing dot"}, {"cve": "CVE-2002-1986", "description": "Source code disclosure using trailing dot"}, {"cve": "CVE-2004-2213", "description": "Source code disclosure using trailing dot"}, {"cve": "CVE-2005-3293", "description": "Source code disclosure using trailing dot"}, {"cve": "CVE-2004-0061", "description": "Bypass directory access restrictions using trailing dot in URL"}], "platforms": {"languages": ["Not Language-Specific"]}}, "420": {"name": "Unprotected Alternate Channel", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product protects a primary channel, but it does not use the same level of protection for an alternate channel.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Identify all alternate channels and use the same protection mechanisms that are used for the primary channels.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2020-8004", "description": "When the internal flash is protected by blocking access on the Data Bus (DBUS), it can still be indirectly accessed through the Instruction Bus (IBUS)..."}, {"cve": "CVE-2002-0567", "description": "DB server assumes that local clients have performed authentication, allowing attacker to directly connect to a process to load libraries and execute c..."}, {"cve": "CVE-2002-1578", "description": "Product does not restrict access to underlying database, so attacker can bypass restrictions by directly querying the database."}, {"cve": "CVE-2003-1035", "description": "User can avoid lockouts by using an API instead of the GUI to conduct brute force password guessing."}, {"cve": "CVE-2002-1863", "description": "FTP service can not be disabled even when other access controls would require it."}], "platforms": {"languages": ["Not Language-Specific"]}}, "421": {"name": "Race Condition During Access to Alternate Channel", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product opens an alternate channel to communicate with an authorized user, but the channel is accessible to other actors.", "extended_description": "This creates a race condition that allows an attacker to access the channel before the authorized user does.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity", "Bypass Protection Mechanism"]}], "observed_examples": [{"cve": "CVE-1999-0351", "description": "FTP \"Pizza Thief\" vulnerability. Attacker can connect to a port that was intended for use by another client."}, {"cve": "CVE-2003-0230", "description": "Product creates Windows named pipe during authentication that another attacker can hijack by connecting to it."}], "platforms": {"languages": ["Not Language-Specific"]}}, "422": {"name": "Unprotected Windows Messaging Channel ('Shatter')", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly verify the source of a message in the Windows Messaging System while running at elevated privileges, creating an alternate channel through which an attacker can directly send a message to the product.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Always verify and authenticate the source of the message.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2002-0971", "description": "Bypass GUI and access restricted dialog box."}, {"cve": "CVE-2002-1230", "description": "Gain privileges via Windows message."}, {"cve": "CVE-2003-0350", "description": "A control allows a change to a pointer for a callback function using Windows message."}, {"cve": "CVE-2003-0908", "description": "Product launches Help functionality while running with raised privileges, allowing command execution using Windows message to access \"open file\" dialo..."}, {"cve": "CVE-2004-0213", "description": "Attacker uses Shatter attack to bypass GUI-enforced protection for CVE-2003-0908."}], "platforms": {"languages": ["Not Language-Specific"]}}, "423": {"name": "DEPRECATED: Proxied Trusted Channel", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "This entry has been deprecated because it was a duplicate of CWE-441. All content has been transferred to CWE-441."}, "424": {"name": "Improper Protection of Alternate Path", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Deploy different layers of protection to implement security in depth.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2022-29238", "description": "Access-control setting in web-based document collaboration tool is not properly implemented by the code, which prevents listing hidden directories but..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "425": {"name": "Direct Request ('Forced Browsing')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.", "extended_description": "Web applications susceptible to direct request attacks often make the false assumption that such resources can only be reached through a given navigation path and so only apply authorization at certain points in the path.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Read Application Data", "Modify Application Data", "Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Apply appropriate access control authorizations for each access to all restricted URLs, scripts or files.", "phase": ["Architecture and Design", "Operation"]}, {"description": "Consider using MVC based frameworks such as Struts.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2022-29238", "description": "Access-control setting in web-based document collaboration tool is not properly implemented by the code, which prevents listing hidden directories but..."}, {"cve": "CVE-2022-23607", "description": "Python-based HTTP library did not scope cookies to a particular domain such that \"supercookies\" could be sent to any domain on redirect."}, {"cve": "CVE-2004-2144", "description": "Bypass authentication via direct request."}, {"cve": "CVE-2005-1892", "description": "Infinite loop or infoleak triggered by direct requests."}, {"cve": "CVE-2004-2257", "description": "Bypass auth/auth via direct request."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "426": {"name": "Untrusted Search Path", "abstraction": "Base", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability", "Access Control"], "impact": ["Gain Privileges or Assume Identity", "Execute Unauthorized Code or Commands"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Confidentiality"], "impact": ["Read Files or Directories"]}], "mitigations": [{"description": "Hard-code the search path to a set of known-safe values (such as system directories), or only allow them to be specified by the administrator in a configuration file. Do not allow these settings to be modified by an external party. Be careful to avoid related weaknesses such as CWE-426 and CWE-428.", "phase": ["Architecture and Design", "Implementation"]}, {"description": "When invoking other programs, specify those programs using fully-qualified pathnames. While this is an effective approach, code that uses fully-qualified pathnames might not be portable to other systems that do not use the same pathnames. The portability can be improved by locating the full-qualifie...", "phase": ["Implementation"]}, {"description": "Remove or restrict all environment settings before invoking other programs. This includes the PATH environment variable, LD_LIBRARY_PATH, and other settings that identify the location of code libraries, and any application-specific search paths.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Black Box"}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Manual Analysis", "description": "Use tools and techniques that require manual (human) analysis, such as penetration testing, threat modeling, and interactive tools that allow the tester to record and modify an active session. These m..."}], "observed_examples": [{"cve": "CVE-1999-1120", "description": "Application relies on its PATH environment variable to find and execute program."}, {"cve": "CVE-2008-1810", "description": "Database application relies on its PATH environment variable to find and execute program."}, {"cve": "CVE-2007-2027", "description": "Chain: untrusted search path enabling resultant format string by loading malicious internationalization messages."}, {"cve": "CVE-2008-3485", "description": "Untrusted search path using malicious .EXE in Windows environment."}, {"cve": "CVE-2008-2613", "description": "setuid program allows compromise using path that finds and loads a malicious library."}], "platforms": {"languages": ["Not Language-Specific"]}}, "427": {"name": "Uncontrolled Search Path Element", "abstraction": "Base", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Hard-code the search path to a set of known-safe values (such as system directories), or only allow them to be specified by the administrator in a configuration file. Do not allow these settings to be modified by an external party. Be careful to avoid related weaknesses such as CWE-426 and CWE-428.", "phase": ["Architecture and Design", "Implementation"]}, {"description": "When invoking other programs, specify those programs using fully-qualified pathnames. While this is an effective approach, code that uses fully-qualified pathnames might not be portable to other systems that do not use the same pathnames. The portability can be improved by locating the full-qualifie...", "phase": ["Implementation"]}, {"description": "Remove or restrict all environment settings before invoking other programs. This includes the PATH environment variable, LD_LIBRARY_PATH, and other settings that identify the location of code libraries, and any application-specific search paths.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2023-25815", "description": "chain: a change in an underlying package causes the gettext function to use implicit initialization with a hard-coded path (CWE-1419) under the user-w..."}, {"cve": "CVE-2022-4826", "description": "Go-based git extension on Windows can search for and execute a malicious \"..exe\" in a repository because Go searches the current working directory if ..."}, {"cve": "CVE-2020-26284", "description": "A Static Site Generator built in Go, when running on Windows, searches the current working directory for a command, possibly allowing code execution u..."}, {"cve": "CVE-2022-24765", "description": "Windows-based fork of git creates a \".git\" folder in the C: drive, allowing local attackers to create a .git folder with a malicious config file"}, {"cve": "CVE-2019-1552", "description": "SSL package searches under \"C:/usr/local\" for configuration files and other critical data, but C:/usr/local might be world-writable."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "428": {"name": "Unquoted Search Path or Element", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.", "extended_description": "If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as \"C:\\Program.exe\" to be run by a privileged program making use of WinExec.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Properly quote the full search path before executing a program on the system.", "phase": ["Implementation"]}, {"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2005-1185", "description": "Small handful of others. Program doesn't quote the \"C:\\Program Files\\\" path when calling a program to be executed - or any other path with a directory..."}, {"cve": "CVE-2005-2938", "description": "CreateProcess() and CreateProcessAsUser() can be misused by applications to allow \"program.exe\" style attacks in C:"}, {"cve": "CVE-2000-1128", "description": "Applies to \"Common Files\" folder, with a malicious common.exe, instead of \"Program Files\"/program.exe."}], "platforms": {"languages": ["Not Language-Specific"]}}, "43": {"name": "Path Equivalence: 'filename....' (Multiple Trailing Dot)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts path input in the form of multiple trailing dot ('filedir....') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "observed_examples": [{"cve": "CVE-2004-0281", "description": "Multiple trailing dot allows directory listing"}], "platforms": {"languages": ["Not Language-Specific"]}}, "430": {"name": "Deployment of Wrong Handler", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The wrong \"handler\" is assigned to process an object.", "extended_description": "An example of deploying the wrong handler would be calling a servlet to reveal source code of a .JSP file, or automatically \"determining\" type of the object even if it is contradictory to an explicitly specified type.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Varies by Context", "Unexpected State"]}], "mitigations": [{"description": "Perform a type check before interpreting an object.", "phase": ["Architecture and Design"]}, {"description": "Reject any inconsistent types, such as a file with a .GIF extension that appears to consist of PHP code.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2001-0004", "description": "Source code disclosure via manipulated file extension that causes parsing by wrong DLL."}, {"cve": "CVE-2002-0025", "description": "Web browser does not properly handle the Content-Type header field, causing a different application to process the document."}, {"cve": "CVE-2000-1052", "description": "Source code disclosure by directly invoking a servlet."}, {"cve": "CVE-2002-1742", "description": "Arbitrary Perl functions can be loaded by calling a non-existent function that activates a handler."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "431": {"name": "Missing Handler", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A handler is not available or implemented.", "extended_description": "When an exception is thrown and not caught, the process has given up an opportunity to decide if a given failure or event is worth a change in execution.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Handle all possible situations (e.g. error condition).", "phase": ["Implementation"]}, {"description": "If an operation can throw an Exception, implement a handler for that specific exception.", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2022-25302", "description": "SDK for OPC Unified Architecture (OPC UA) is missing a handler for when a cast fails, allowing for a crash"}], "platforms": {"languages": ["Not Language-Specific"]}}, "432": {"name": "Dangerous Signal Handler not Disabled During Sensitive Operations", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a signal handler that shares state with other signal handlers, but it does not properly mask or prevent those signal handlers from being invoked while the original signal handler is still running.", "extended_description": "During the execution of a signal handler, it can be interrupted by another handler when a different signal is sent. If the two handlers share state - such as global variables - then an attacker can corrupt the state by sending another signal before the first handler has completed execution.", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}], "mitigations": [{"description": "Turn off dangerous handlers when performing sensitive operations.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "433": {"name": "Unparsed Raw Web Content Delivery", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores raw content or supporting code under the web document root with an extension that is not specifically handled by the server.", "extended_description": "If code is stored in a file with an extension such as \".inc\" or \".pl\", and the web server does not have a handler for that extension, then the server will likely send the contents of the file directly to the requester without the pre-processing that was expected. When that file contains sensitive information such as database credentials, this may allow the attacker to compromise the application or associated components.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Perform a type check before interpreting files.", "phase": ["Architecture and Design"]}, {"description": "Do not store sensitive information in files which may be misinterpreted.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2002-1886", "description": "\".inc\" file stored under web document root and returned unparsed by the server"}, {"cve": "CVE-2002-2065", "description": "\".inc\" file stored under web document root and returned unparsed by the server"}, {"cve": "CVE-2005-2029", "description": "\".inc\" file stored under web document root and returned unparsed by the server"}, {"cve": "CVE-2001-0330", "description": "direct request to .pl file leaves it unparsed"}, {"cve": "CVE-2002-0614", "description": ".inc file"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "434": {"name": "Unrestricted Upload of File with Dangerous Type", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Generate a new, unique filename for an uploaded file instead of using the user-supplied filename, so that no external input is used at all.[REF-422] [REF-423]", "phase": ["Architecture and Design"]}, {"description": "When the set of acceptable objects, such as filenames or URLs, is limited or known, create a mapping from a set of fixed input values (such as numeric IDs) to the actual filenames or URLs, and reject all other inputs.", "phase": ["Architecture and Design"]}, {"description": "Consider storing the uploaded files outside of the web document root entirely. Then, use other mechanisms to deliver the files dynamically. [REF-423]", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Dynamic Analysis with Automated Results Interpretation"}, {"method": "Dynamic Analysis with Manual Results Interpretation"}, {"method": "Manual Static Analysis - Source Code"}], "observed_examples": [{"cve": "CVE-2023-5227", "description": "PHP-based FAQ management app does not check the MIME type for uploaded images"}, {"cve": "CVE-2001-0901", "description": "Web-based mail product stores \".shtml\" attachments that could contain SSI"}, {"cve": "CVE-2002-1841", "description": "PHP upload does not restrict file types"}, {"cve": "CVE-2005-1868", "description": "upload and execution of .php file"}, {"cve": "CVE-2005-1881", "description": "upload file with dangerous extension"}], "platforms": {"languages": ["ASP.NET", "PHP", "Not Language-Specific"], "technologies": ["Web Server"]}}, "435": {"name": "Improper Interaction Between Multiple Correctly-Behaving Entities", "abstraction": "Pillar", "mapping": "DISCOURAGED", "structure": "Simple", "description": "An interaction error occurs when two entities have correct behavior when running independently of each other, but when they are integrated as components in a larger system or process, they introduce incorrect behaviors that may cause resultant weaknesses.", "extended_description": "When a system or process combines multiple independent components, this often produces new, emergent behaviors at the system level.  However, if the interactions between these components are not fully accounted for, some of the emergent behaviors can be incorrect or even insecure.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State", "Varies by Context"]}], "observed_examples": [{"cve": "CVE-2002-0485", "description": "Anti-virus product allows bypass via Content-Type and Content-Disposition headers that are mixed case, which are still processed by some clients."}, {"cve": "CVE-2003-0411", "description": "chain: Code was ported from a case-sensitive Unix platform to a case-insensitive Windows platform where filetype handlers treat .jsp and .JSP as diffe..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "436": {"name": "Interpretation Conflict", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.", "extended_description": "This is generally found in proxies, firewalls, anti-virus software, and other intermediary devices that monitor, allow, deny, or modify traffic based on how the client or server is expected to behave.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Unexpected State", "Varies by Context"]}], "observed_examples": [{"cve": "CVE-2005-1215", "description": "Bypass filters or poison web cache using requests with multiple Content-Length headers, a non-standard behavior."}, {"cve": "CVE-2002-0485", "description": "Anti-virus product allows bypass via Content-Type and Content-Disposition headers that are mixed case, which are still processed by some clients."}, {"cve": "CVE-2002-1978", "description": "FTP clients sending a command with \"PASV\" in the argument can cause firewalls to misinterpret the server's error as a valid response, allowing filter ..."}, {"cve": "CVE-2002-1979", "description": "FTP clients sending a command with \"PASV\" in the argument can cause firewalls to misinterpret the server's error as a valid response, allowing filter ..."}, {"cve": "CVE-2002-0637", "description": "Virus product bypass with spaces between MIME header fields and the \":\" separator, a non-standard message that is accepted by some clients."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "437": {"name": "Incomplete Model of Endpoint Features", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A product acts as an intermediary or monitor between two or more endpoints, but it does not have a complete model of an endpoint's features, behaviors, or state, potentially causing the product to perform incorrect actions based on this incomplete model.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Unexpected State", "Varies by Context"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "439": {"name": "Behavioral Change in New Version or Environment", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A's behavior or functionality changes with a new version of A, or a new environment, which is not known (or manageable) by B.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation", "Varies by Context"]}], "observed_examples": [{"cve": "CVE-2002-1976", "description": "Linux kernel 2.2 and above allow promiscuous mode using a different method than previous versions, and ifconfig is not aware of the new method (altern..."}, {"cve": "CVE-2005-1711", "description": "Product uses defunct method from another product that does not return an error code and allows detection avoidance."}, {"cve": "CVE-2003-0411", "description": "chain: Code was ported from a case-sensitive Unix platform to a case-insensitive Windows platform where filetype handlers treat .jsp and .JSP as diffe..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "44": {"name": "Path Equivalence: 'file.name' (Internal Dot)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts path input in the form of internal dot ('file.ordir') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "440": {"name": "Expected Behavior Violation", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A feature, API, or function does not perform according to its specification.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation", "Varies by Context"]}], "observed_examples": [{"cve": "CVE-2003-0187", "description": "Program uses large timeouts on unconfirmed connections resulting from inconsistency in linked lists implementations."}, {"cve": "CVE-2003-0465", "description": "\"strncpy\" in Linux kernel acts different than libc on x86, leading to expected behavior difference - sort of a multiple interpretation error?"}, {"cve": "CVE-2005-3265", "description": "Buffer overflow in product stems the use of a third party library function that is expected to have internal protection against overflows, but doesn't..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["ICS/OT"]}}, "441": {"name": "Unintended Proxy or Intermediary ('Confused Deputy')", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.", "consequences": [{"scope": ["Non-Repudiation", "Access Control"], "impact": ["Gain Privileges or Assume Identity", "Hide Activities", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Enforce the use of strong mutual authentication mechanism between the two parties.", "phase": ["Architecture and Design"]}, {"description": "Whenever a product is an intermediary or proxy for\n                   transactions between two other components, the proxy core\n                   should not drop the identity of the initiator of the\n                   transaction. The immutability of the identity of the\n                   initiator...", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-1999-0017", "description": "FTP bounce attack. The design of the protocol allows an attacker to modify the PORT command to cause the FTP server to connect to other machines besid..."}, {"cve": "CVE-1999-0168", "description": "RPC portmapper could redirect service requests from an attacker to another entity, which thinks the requests came from the portmapper."}, {"cve": "CVE-2005-0315", "description": "FTP server does not ensure that the IP address in a PORT command is the same as the FTP user's session, allowing port scanning by proxy."}, {"cve": "CVE-2002-1484", "description": "Web server allows attackers to request a URL from another server, including other ports, which allows proxied scanning."}, {"cve": "CVE-2004-2061", "description": "CGI script accepts and retrieves incoming URLs."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "443": {"name": "DEPRECATED: HTTP response splitting", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "This weakness can be found at CWE-113."}, "444": {"name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product acts as an intermediary HTTP agent\n         (such as a proxy or firewall) in the data flow between two\n         entities such as a client and server, but it does not\n         interpret malformed HTTP requests or responses in ways that\n         are consistent with how the messages will be processed by\n         those entities that are at the ultimate destination.", "consequences": [{"scope": ["Integrity", "Non-Repudiation", "Access Control"], "impact": ["Unexpected State", "Hide Activities", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Use a web server that employs a strict HTTP parsing procedure, such as Apache [REF-433].", "phase": ["Implementation"]}, {"description": "Use only SSL communication.", "phase": ["Implementation"]}, {"description": "Terminate the client session after each request.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-24766", "description": "SSL/TLS-capable proxy allows HTTP smuggling when used in tandem with HTTP/1.0 services, due to inconsistent interpretation and input sanitization of H..."}, {"cve": "CVE-2021-37147", "description": "Chain: caching proxy server has improper input validation (CWE-20) of headers, allowing HTTP response smuggling (CWE-444) using an \"LF line ending\""}, {"cve": "CVE-2020-8287", "description": "Node.js platform allows request smuggling via two Transfer-Encoding headers"}, {"cve": "CVE-2006-6276", "description": "Web servers allow request smuggling via inconsistent HTTP headers."}, {"cve": "CVE-2005-2088", "description": "HTTP server allows request smuggling with both a \"Transfer-Encoding: chunked\" header and a Content-Length header"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "446": {"name": "UI Discrepancy for Security Feature", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The user interface does not correctly enable or configure a security feature, but the interface provides feedback that causes the user to believe that the feature is in a secure state.", "extended_description": "When the user interface does not properly reflect what the user asks of it, then it can lead the user into a false sense of security. For example, the user might check a box to enable a security option to enable encrypted communications, but the product does not actually enable the encryption. Alternately, the user might provide a \"restrict ALL\" access control rule, but the product only implements \"restrict SOME\".", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "observed_examples": [{"cve": "CVE-1999-1446", "description": "UI inconsistency; visited URLs list not cleared when \"Clear History\" option is selected."}], "platforms": {"languages": ["Not Language-Specific"]}}, "447": {"name": "Unimplemented or Unsupported Feature in UI", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A UI function for a security feature appears to be supported and gives feedback to the user that suggests that it is supported, but the underlying functionality is not implemented.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context", "Unexpected State"]}], "mitigations": [{"description": "Perform functionality testing before deploying the application.", "phase": ["Testing"]}], "observed_examples": [{"cve": "CVE-2000-0127", "description": "GUI configuration tool does not enable a security option when a checkbox is selected, although that option is honored when manually set in the configu..."}, {"cve": "CVE-2001-0863", "description": "Router does not implement a specific keyword when it is used in an ACL, allowing filter bypass."}, {"cve": "CVE-2001-0865", "description": "Router does not implement a specific keyword when it is used in an ACL, allowing filter bypass."}, {"cve": "CVE-2004-0979", "description": "Web browser does not properly modify security setting when the user sets it."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "448": {"name": "Obsolete Feature in UI", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A UI function is obsolete and the product does not warn the user.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation", "Varies by Context"]}], "mitigations": [{"description": "Remove the obsolete feature from the UI. Warn the user that the feature is no longer supported.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "449": {"name": "The UI Performs the Wrong Action", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The UI performs the wrong action with respect to the user's request.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation", "Varies by Context"]}], "detection_methods": [{"method": "Manual Analysis", "description": "Perform extensive functionality testing of the UI. The UI should behave as specified."}], "observed_examples": [{"cve": "CVE-2001-1387", "description": "Network firewall accidentally implements one command line option as if it were another, possibly leading to behavioral infoleak."}, {"cve": "CVE-2001-0081", "description": "Command line option correctly suppresses a user prompt but does not properly disable a feature, although when the product prompts the user, the featur..."}, {"cve": "CVE-2002-1977", "description": "Product does not \"time out\" according to user specification, leaving sensitive data available after it has expired."}], "platforms": {"languages": ["Not Language-Specific"]}}, "45": {"name": "Path Equivalence: 'file...name' (Multiple Internal Dot)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts path input in the form of multiple internal dot ('file...dir') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "450": {"name": "Multiple Interpretations of UI Input", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The UI has multiple interpretations of user input but does not prompt the user when it selects the less secure interpretation.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "451": {"name": "User Interface (UI) Misrepresentation of Critical Information", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.", "consequences": [{"scope": ["Non-Repudiation", "Access Control"], "impact": ["Hide Activities", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Perform data validation (e.g. syntax, length, etc.) before interpreting the data.", "phase": ["Implementation"]}, {"description": "Create a strategy for presenting information, and plan for how to display unusual characters.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2004-2227", "description": "Web browser's filename selection dialog only shows the beginning portion of long filenames, which can trick users into launching executables with dang..."}, {"cve": "CVE-2001-0398", "description": "Attachment with many spaces in filename bypasses \"dangerous content\" warning and uses different icon. Likely resultant."}, {"cve": "CVE-2001-0643", "description": "Misrepresentation and equivalence issue."}, {"cve": "CVE-2005-0593", "description": "Lock spoofing from several different weaknesses."}, {"cve": "CVE-2004-1104", "description": "Incorrect indicator: web browser can be tricked into presenting the wrong URL"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "453": {"name": "Insecure Default Variable Initialization", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product, by default, initializes an internal variable with an insecure or less secure value than is possible.", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}], "mitigations": [{"description": "Disable or change default settings when they can be used to abuse the system. Since those default settings are shipped with the product they are likely to be known by a potential attacker who is familiar with the product. For instance, default credentials should be changed or the associated accounts...", "phase": ["System Configuration"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-36349", "description": "insecure default variable initialization in BIOS firmware for a hardware board allows DoS"}], "platforms": {"languages": ["PHP", "Not Language-Specific"]}}, "454": {"name": "External Initialization of Trusted Variables or Data Stores", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product initializes critical internal variables or data stores using inputs that can be modified by untrusted actors.", "extended_description": "A product system should be reluctant to trust variables that have been initialized outside of its trust boundary, especially if they are initialized by users. The variables may have been initialized incorrectly. If an attacker can initialize the variable, then they can influence what the vulnerable system will do.", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}], "mitigations": [{"description": "A product system should be reluctant to trust variables that have been initialized outside of its trust boundary. Ensure adequate checking (e.g. input validation) is performed when relying on input from outside a trust boundary.", "phase": ["Implementation"]}, {"description": "Avoid any external control of variables. If necessary, restrict the variables that can be modified using an allowlist, and use a different namespace or naming convention if possible.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-43468", "description": "WordPress module sets internal variables based on external inputs, allowing false reporting of the number of views"}, {"cve": "CVE-2000-0959", "description": "Does not clear dangerous environment variables, enabling symlink attack."}, {"cve": "CVE-2001-0033", "description": "Specify alternate configuration directory in environment variable, enabling untrusted path."}, {"cve": "CVE-2001-0872", "description": "Dangerous environment variable not cleansed."}, {"cve": "CVE-2001-0084", "description": "Specify arbitrary modules using environment variable."}], "platforms": {"languages": ["PHP", "Not Language-Specific"]}}, "455": {"name": "Non-exit on Failed Initialization", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not exit or otherwise modify its operation when security-relevant errors occur during initialization, such as when a configuration file has a format error or a hardware security module (HSM) cannot be activated, which can cause the product to execute in a less secure fashion than intended by the administrator.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Modify Application Data", "Alter Execution Logic"]}], "mitigations": [{"description": "Follow the principle of failing securely when an error occurs. The system should enter a state where it is not vulnerable and will not display sensitive error messages to a potential attacker.", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2005-1345", "description": "Product does not trigger a fatal error if missing or invalid ACLs are in a configuration file."}], "platforms": {"languages": ["Not Language-Specific"]}}, "456": {"name": "Missing Initialization of a Variable", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not initialize critical variables, which causes the execution environment to use unexpected values.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Unexpected State", "Quality Degradation", "Varies by Context"]}], "mitigations": [{"description": "Ensure that critical variables are initialized before first use [REF-1485].", "phase": ["Implementation"]}, {"description": "Choose a language that is not susceptible to these issues.", "phase": ["Requirements"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2020-6078", "description": "Chain: The return value of a function returning a pointer is not checked for success (CWE-252) resulting in the later use of an uninitialized variable..."}, {"cve": "CVE-2019-3836", "description": "Chain: secure communications library does not initialize a local variable for a data structure (CWE-456), leading to access of an uninitialized pointe..."}, {"cve": "CVE-2018-14641", "description": "Chain: C union member is not initialized (CWE-456), leading to access of invalid pointer (CWE-824)"}, {"cve": "CVE-2009-2692", "description": "Chain: Use of an unimplemented network socket operation pointing to an uninitialized handler function (CWE-456) causes a crash because of a null point..."}, {"cve": "CVE-2020-20739", "description": "A variable that has its value set in a conditional statement is sometimes used when the conditional fails, sometimes causing data leakage"}], "platforms": {"languages": ["Not Language-Specific"]}}, "457": {"name": "Use of Uninitialized Variable", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The code uses a variable that has not been initialized, leading to unpredictable or unintended results.", "extended_description": "In some languages such as C and C++, stack variables are not initialized by default. They generally contain junk data with the contents of stack memory before the function was invoked. An attacker can sometimes control or read these contents. In other languages or conditions, a variable that is not explicitly initialized can be given a default value that has security implications, depending on the logic of the program. The presence of an uninitialized variable can sometimes indicate a typographi...", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Availability", "Integrity", "Other"], "impact": ["Other"]}, {"scope": ["Authorization", "Other"], "impact": ["Other"]}], "mitigations": [{"description": "Ensure that critical variables are initialized before first use [REF-1485].", "phase": ["Implementation"]}, {"description": "Most compilers will complain about the use of uninitialized variables if warnings are turned on.", "phase": ["Build and Compilation"]}, {"description": "When using a language that does not require explicit declaration of variables, run or compile the software in a mode that reports undeclared or unknown variables. This may indicate the presence of a typographic error in the variable's name.", "phase": ["Implementation", "Operation"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2019-15900", "description": "Chain: sscanf() call is used to check if a username and group exists, but the return value of sscanf() call is not checked (CWE-252), causing an unini..."}, {"cve": "CVE-2008-3688", "description": "Chain: A denial of service may be caused by an uninitialized variable (CWE-457) allowing an infinite loop (CWE-835) resulting from a connection to an ..."}, {"cve": "CVE-2008-0081", "description": "Uninitialized variable leads to code execution in popular desktop application."}, {"cve": "CVE-2007-4682", "description": "Crafted input triggers dereference of an uninitialized object pointer."}, {"cve": "CVE-2007-3468", "description": "Crafted audio file triggers crash when an uninitialized variable is used."}], "platforms": {"languages": ["C", "C++", "Perl", "PHP", "Not Language-Specific"]}}, "458": {"name": "DEPRECATED: Incorrect Initialization", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "This weakness has been deprecated because its name and description did not match. The description duplicated CWE-454, while the name suggested a more abstract initialization problem. Please refer to CWE-665 for the more abstract problem."}, "459": {"name": "Incomplete Cleanup", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly \"clean up\" and remove temporary or supporting resources after they have been used.", "consequences": [{"scope": ["Other", "Confidentiality", "Integrity"], "impact": ["Other", "Read Application Data", "Modify Application Data", "DoS: Resource Consumption (Other)"]}], "mitigations": [{"description": "Temporary files and other supporting resources should be deleted/released immediately after they are no longer needed.", "phase": ["Architecture and Design", "Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2000-0552", "description": "World-readable temporary file not deleted after use."}, {"cve": "CVE-2005-2293", "description": "Temporary file not deleted after use, leaking database usernames and passwords."}, {"cve": "CVE-2002-0788", "description": "Interaction error creates a temporary file that can not be deleted due to strong permissions."}, {"cve": "CVE-2002-2066", "description": "Alternate data streams for NTFS files are not cleared when files are wiped (alternate channel / infoleak)."}, {"cve": "CVE-2002-2067", "description": "Alternate data streams for NTFS files are not cleared when files are wiped (alternate channel / infoleak)."}], "platforms": {"languages": ["Not Language-Specific"]}}, "46": {"name": "Path Equivalence: 'filename ' (Trailing Space)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts path input in the form of trailing space ('filedir ') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "observed_examples": [{"cve": "CVE-2001-0693", "description": "Source disclosure via trailing encoded space \"%20\""}, {"cve": "CVE-2001-0778", "description": "Source disclosure via trailing encoded space \"%20\""}, {"cve": "CVE-2001-1248", "description": "Source disclosure via trailing encoded space \"%20\""}, {"cve": "CVE-2004-0280", "description": "Source disclosure via trailing encoded space \"%20\""}, {"cve": "CVE-2004-2213", "description": "Source disclosure via trailing encoded space \"%20\""}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "460": {"name": "Improper Cleanup on Thrown Exception", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not clean up its state or incorrectly cleans up its state when an exception is thrown, leading to unexpected state or control flow.", "extended_description": "Often, when functions or loops become complicated, some level of resource cleanup is needed throughout execution. Exceptions can disturb the flow of the code and prevent the necessary cleanup from happening.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "If one breaks from a loop or function by throwing an exception, make sure that cleanup happens or that you should exit the program. Use throwing exceptions sparsely.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C", "C++", "Java", "C#"]}}, "462": {"name": "Duplicate Key in Associative List (Alist)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Duplicate keys in associative lists can lead to non-unique keys being mistaken for an error.", "extended_description": "A duplicate key entry -- if the alist is designed properly -- could be used as a constant time replace function. However, duplicate key entries could be inserted by mistake. Because of this ambiguity, duplicate key entries in an association list are not recommended and should not be allowed.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation", "Varies by Context"]}], "mitigations": [{"description": "Use a hash table instead of an alist.", "phase": ["Architecture and Design"]}, {"description": "Use an alist which checks the uniqueness of hash keys with each entry before inserting the entry.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["C", "C++", "Java", "C#"]}}, "463": {"name": "Deletion of Data Structure Sentinel", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The accidental deletion of a data-structure sentinel can cause serious programming logic problems.", "extended_description": "Often times data-structure sentinels are used to mark structure of the data structure. A common example of this is the null character at the end of strings. Another common example is linked lists which may contain a sentinel to mark the end of the list. It is dangerous to allow this type of control data to be easily accessible. Therefore, it is important to protect from the deletion or modification outside of some wrapper interface which provides safety.", "consequences": [{"scope": ["Availability", "Other"], "impact": ["Other"]}, {"scope": ["Authorization", "Other"], "impact": ["Other"]}], "mitigations": [{"description": "Use an abstraction library to abstract away risky APIs. Not a complete solution.", "phase": ["Architecture and Design"]}, {"description": "Use OS-level preventative functionality. Not a complete solution.", "phase": ["Operation"]}], "platforms": {"languages": ["C", "C++"]}}, "464": {"name": "Addition of Data Structure Sentinel", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The accidental addition of a data-structure sentinel can cause serious programming logic problems.", "extended_description": "Data-structure sentinels are often used to mark the structure of data. A common example of this is the null character at the end of strings or a special sentinel to mark the end of a linked list. It is dangerous to allow this type of control data to be easily accessible. Therefore, it is important to protect from the addition or modification of sentinels.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}], "mitigations": [{"description": "Encapsulate the user from interacting with data sentinels. Validate user input to verify that sentinels are not present.", "phase": ["Implementation", "Architecture and Design"]}, {"description": "Proper error checking can reduce the risk of inadvertently introducing sentinel values into data. For example, if a parsing function fails or encounters an error, it might return a value that is the same as the sentinel.", "phase": ["Implementation"]}, {"description": "Use an abstraction library to abstract away risky APIs. This is not a complete solution.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["C", "C++"]}}, "466": {"name": "Return of Pointer Value Outside of Expected Range", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A function can return a pointer to memory that is outside of the buffer that the pointer is expected to reference.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Memory", "Modify Memory"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "467": {"name": "Use of sizeof() on a Pointer Type", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The code calls sizeof() on a pointer type, which can be an incorrect calculation if the programmer intended to determine the size of the data that is being pointed to.", "extended_description": "The use of sizeof() on a pointer can sometimes generate useful information. An obvious case is to find out the wordsize on a platform. More often than not, the appearance of sizeof(pointer) indicates a bug.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality"], "impact": ["Modify Memory", "Read Memory"]}], "mitigations": [{"description": "Use expressions such as \"sizeof(*pointer)\" instead of \"sizeof(pointer)\", unless you intend to run sizeof() on a pointer type to gain some platform independence or if you are allocating a variable on the stack.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C", "C++"]}}, "468": {"name": "Incorrect Pointer Scaling", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "In C and C++, one may often accidentally refer to the wrong memory due to the semantics of when math operations are implicitly scaled.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Memory", "Modify Memory"]}], "mitigations": [{"description": "Use a platform with high-level memory abstractions.", "phase": ["Architecture and Design"]}, {"description": "Always use array indexing instead of direct pointer manipulation.", "phase": ["Implementation"]}, {"description": "Use technologies for preventing buffer overflows.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C", "C++"]}}, "469": {"name": "Use of Pointer Subtraction to Determine Size", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product subtracts one pointer from another in order to determine size, but this calculation can be incorrect if the pointers do not exist in the same memory chunk.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Access Control", "Integrity", "Confidentiality", "Availability"], "impact": ["Modify Memory", "Read Memory", "Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Save an index variable. This is the recommended solution. Rather than subtract pointers from one another, use an index variable of the same size as the pointers in question. Use this variable to \"walk\" from one pointer to the other and calculate the difference. Always validate this number.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C", "C++"]}}, "47": {"name": "Path Equivalence: ' filename' (Leading Space)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts path input in the form of leading space (' filedir') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "470": {"name": "Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.", "extended_description": "If the product uses external inputs to determine which class to instantiate or which method to invoke, then an attacker could supply values to select unexpected classes or methods. If this occurs, then the attacker could create control flow paths that were not intended by the developer. These paths could bypass authentication or access control checks, or otherwise cause the product to behave in an unexpected manner. This situation becomes a doomsday scenario if the attacker can upload files into...", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability", "Other"], "impact": ["Execute Unauthorized Code or Commands", "Alter Execution Logic"]}, {"scope": ["Availability", "Other"], "impact": ["DoS: Crash, Exit, or Restart", "Other"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Refactor your code to avoid using reflection.", "phase": ["Architecture and Design"]}, {"description": "Do not use user-controlled inputs to select and load classes or code.", "phase": ["Architecture and Design"]}, {"description": "Apply strict input validation by using allowlists or indirect selection to ensure that the user is only selecting allowable classes or code.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2018-1000613", "description": "Cryptography API uses unsafe reflection when deserializing a private key"}, {"cve": "CVE-2004-2331", "description": "Database system allows attackers to bypass sandbox restrictions by using the Reflection API."}], "platforms": {"languages": ["Java", "PHP", "Interpreted"]}}, "471": {"name": "Modification of Assumed-Immutable Data (MAID)", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly protect an assumed-immutable element from being modified by an attacker.", "extended_description": "This occurs when a particular input is critical enough to the functioning of the application that it should not be modifiable at all, but it is. Certain resources are often assumed to be immutable when they are not, such as hidden form fields in web applications, cookies, and reverse DNS lookups.", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}, {"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "When the data is stored or transmitted through untrusted sources that could modify the data, implement integrity checks to detect unauthorized modification, or store/transmit the data in a trusted location that is free from external influence.", "phase": ["Architecture and Design", "Operation", "Implementation"]}], "observed_examples": [{"cve": "CVE-2002-1757", "description": "Relies on $PHP_SELF variable for authentication."}, {"cve": "CVE-2005-1905", "description": "Gain privileges by modifying assumed-immutable code addresses that are accessed by a driver."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "472": {"name": "External Control of Assumed-Immutable Web Parameter", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2002-0108", "description": "Forum product allows spoofed messages of other users via hidden form fields for name and e-mail address."}, {"cve": "CVE-2000-0253", "description": "Shopping cart allows price modification via hidden form field."}, {"cve": "CVE-2000-0254", "description": "Shopping cart allows price modification via hidden form field."}, {"cve": "CVE-2000-0926", "description": "Shopping cart allows price modification via hidden form field."}, {"cve": "CVE-2000-0101", "description": "Shopping cart allows price modification via hidden form field."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "473": {"name": "PHP External Variable Modification", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "A PHP application does not properly protect against the modification of variables from external sources, such as query parameters or cookies. This can expose the application to numerous weaknesses that would not exist otherwise.", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}], "mitigations": [{"description": "Carefully identify which variables can be controlled or influenced by an external user, and consider adopting a naming convention to emphasize when externally modifiable variables are being used. An application should be reluctant to trust variables that have been initialized outside of its trust bo...", "phase": ["Requirements", "Implementation"]}], "observed_examples": [{"cve": "CVE-2000-0860", "description": "File upload allows arbitrary file read by setting hidden form variables to match internal variable names."}, {"cve": "CVE-2001-0854", "description": "Mistakenly trusts $PHP_SELF variable to determine if include script was called by its parent."}, {"cve": "CVE-2002-0764", "description": "PHP remote file inclusion by modified assumed-immutable variable."}, {"cve": "CVE-2001-1025", "description": "Modify key variable when calling scripts that don't load a library that initializes it."}, {"cve": "CVE-2003-0754", "description": "Authentication bypass by modifying array used for authentication."}], "platforms": {"languages": ["PHP"]}}, "474": {"name": "Use of Function with Inconsistent Implementations", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The code uses a function that has inconsistent implementations across operating systems and versions.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation", "Varies by Context"]}], "mitigations": [{"description": "Do not accept inconsistent behavior from the API specifications when the deviant behavior increase the risk level.", "phase": ["Architecture and Design", "Requirements"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C", "PHP", "Not Language-Specific"]}}, "475": {"name": "Undefined Behavior for Input to API", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The behavior of this function is undefined unless its control parameter is set to a specific value.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation", "Varies by Context"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "476": {"name": "NULL Pointer Dereference", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product dereferences a pointer that it expects to be valid but is NULL.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Integrity", "Confidentiality"], "impact": ["Execute Unauthorized Code or Commands", "Read Memory", "Modify Memory"]}], "mitigations": [{"description": "For any pointers that could have been modified or provided from a function that can return NULL, check the pointer for NULL before use. When working with a multithreaded or otherwise asynchronous environment, ensure that proper locking APIs are used to lock before the check, and unlock when it has f...", "phase": ["Implementation"]}, {"description": "Select a programming language that is not susceptible to these issues.", "phase": ["Requirements"]}, {"description": "Check the results of all functions that return a value and verify that the value is non-null before acting upon it.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Dynamic Analysis", "description": "This weakness can be detected using dynamic tools and techniques that interact with the software using large test suites with many diverse inputs, such as fuzz testing (fuzzing), robustness testing, a..."}, {"method": "Manual Dynamic Analysis", "description": "Identify error conditions that are not likely to occur during normal usage and trigger them. For example, run the program under low memory conditions, run with insufficient privileges or permissions, ..."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2024-41130", "description": "C++ library for LLM inference has NULL pointer dereference if a read operation fails"}, {"cve": "CVE-2005-3274", "description": "race condition causes a table to be corrupted if a timer activates while it is being modified, leading to resultant NULL dereference; also involves lo..."}, {"cve": "CVE-2002-1912", "description": "large number of packets leads to NULL dereference"}, {"cve": "CVE-2005-0772", "description": "packet with invalid error status value triggers NULL dereference"}, {"cve": "CVE-2009-4895", "description": "Chain: race condition for an argument value, possibly resulting in NULL dereference"}], "platforms": {"languages": ["C", "C++", "Java", "C#", "Go"]}}, "477": {"name": "Use of Obsolete Function", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The code uses deprecated or obsolete functions, which suggests that the code has not been actively reviewed or maintained.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "mitigations": [{"description": "Refer to the documentation for the obsolete function in order to determine why it is deprecated or obsolete and to learn about alternative ways to achieve the same functionality.", "phase": ["Implementation"]}, {"description": "Consider seriously the security implications of using an obsolete function. Consider using alternate functions.", "phase": ["Requirements"]}], "detection_methods": [{"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Manual Static Analysis - Binary or Bytecode"}, {"method": "Dynamic Analysis with Manual Results Interpretation"}], "platforms": {"languages": ["Not Language-Specific"]}}, "478": {"name": "Missing Default Case in Multiple Condition Expression", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The code does not have a default case in an expression with multiple conditions, such as a switch statement.", "extended_description": "If a multiple-condition expression (such as a switch in C) omits the default case but does not consider or handle all possible values that could occur, then this might lead to complex logical errors and resultant weaknesses. Because of this, further decisions are made based on poor information, and cascading failure results. This cascading failure may result in any number of security issues, and constitutes a significant failure in the system.", "consequences": [{"scope": ["Integrity"], "impact": ["Varies by Context", "Alter Execution Logic"]}], "mitigations": [{"description": "Ensure that there are no cases unaccounted for when adjusting program flow or values based on the value of a given variable. In the case of switch style statements, the very simple act of creating a default case can, if done correctly, mitigate this situation. Often however, the default case is used...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C", "C++", "Java", "C#", "Python", "JavaScript"]}}, "479": {"name": "Signal Handler Use of a Non-reentrant Function", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product defines a signal handler that calls a non-reentrant function.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Integrity"], "impact": ["Modify Memory", "Modify Application Data"]}], "mitigations": [{"description": "Require languages or libraries that provide reentrant functionality, or otherwise make it easier to avoid this weakness.", "phase": ["Requirements"]}, {"description": "Design signal handlers to only set flags rather than perform complex functionality.", "phase": ["Architecture and Design"]}, {"description": "Ensure that non-reentrant functions are not found in signal handlers.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2005-0893", "description": "signal handler calls function that ultimately uses malloc()"}, {"cve": "CVE-2004-2259", "description": "SIGCHLD signal to FTP server can cause crash under heavy load while executing non-reentrant functions like malloc/free."}], "platforms": {"languages": ["C", "C++"]}}, "48": {"name": "Path Equivalence: 'file name' (Internal Whitespace)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts path input in the form of internal space ('file(SPACE)name') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "observed_examples": [{"cve": "CVE-2000-0293", "description": "Filenames with spaces allow arbitrary file deletion when the product does not properly quote them; some overlap with path traversal."}, {"cve": "CVE-2001-1567", "description": "\"+\" characters in query string converted to spaces before sensitive file/extension (internal space), leading to bypass of access restrictions to the f..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "480": {"name": "Use of Incorrect Operator", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accidentally uses the wrong operator, which changes the logic in security-relevant ways.", "extended_description": "These types of errors are generally the result of a typo by the programmer.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Other"], "impact": ["Alter Execution Logic"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "This weakness can be found easily using static analysis. However in some cases an operator might appear to be incorrect, but is actually correct and reflects unusual logic within the program."}, {"method": "Manual Static Analysis", "description": "This weakness can be found easily using static analysis. However in some cases an operator might appear to be incorrect, but is actually correct and reflects unusual logic within the program."}], "observed_examples": [{"cve": "CVE-2022-3979", "description": "Chain: data visualization program written in PHP uses the \"!=\" operator instead of the type-strict \"!==\" operator (CWE-480) when validating hash value..."}, {"cve": "CVE-2021-3116", "description": "Chain: Python-based HTTP Proxy server uses the wrong boolean operators (CWE-480) causing an  incorrect comparison (CWE-697) that identifies an authN f..."}], "platforms": {"languages": ["C", "C++", "Perl", "Not Language-Specific"]}}, "481": {"name": "Assigning instead of Comparing", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The code uses an operator for assignment when the intention was to perform a comparison.", "extended_description": "In many languages the compare statement is very close in appearance to the assignment statement and are often confused. This bug is generally the result of a typo and usually causes obvious problems with program execution. If the comparison is in an if statement, the if statement will usually evaluate the value of the right-hand side of the predicate.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Other"], "impact": ["Alter Execution Logic"]}], "mitigations": [{"description": "Many IDEs and static analysis products will detect this problem.", "phase": ["Testing"]}, {"description": "Place constants on the left. If one attempts to assign a constant with a variable, the compiler will produce an error.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C", "C++", "Java", "C#"]}}, "482": {"name": "Comparing instead of Assigning", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The code uses an operator for comparison when the intention was to perform an assignment.", "extended_description": "In many languages, the compare statement is very close in appearance to the assignment statement; they are often confused.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Availability", "Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Many IDEs and static analysis products will detect this problem.", "phase": ["Testing"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C", "C++"]}}, "483": {"name": "Incorrect Block Delimitation", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The code does not explicitly delimit a block that is intended to contain 2 or more statements, creating a logic error.", "extended_description": "In some languages, braces (or other delimiters) are optional for blocks. When the delimiter is omitted, it is possible to insert a logic error in which a statement is thought to be in a block but is not. In some cases, the logic error can have security implications.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Alter Execution Logic"]}], "mitigations": [{"description": "Always use explicit block delimitation and use static-analysis technologies to enforce this practice.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2014-1266", "description": "Chain: incorrect \"goto\" in Apple SSL product bypasses certificate validation, allowing Adversary-in-the-Middle (AITM) attack (Apple \"goto fail\" bug). ..."}], "platforms": {"languages": ["C", "C++"]}}, "484": {"name": "Omitted Break Statement in Switch", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product omits a break statement within a switch or similar construct, causing code associated with multiple conditions to execute. This can cause problems when the programmer only intended to execute code associated with one condition.", "extended_description": "This can lead to critical code executing in situations where it should not.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Other"], "impact": ["Alter Execution Logic"]}], "mitigations": [{"description": "Omitting a break statement so that one may fall through is often indistinguishable from an error, and therefore should be avoided. If you need to use fall-through capabilities, make sure that you have clearly documented this within the switch statement, and ensure that you have examined all the logi...", "phase": ["Implementation"]}, {"description": "The functionality of omitting a break statement could be clarified with an if statement. This method is much safer.", "phase": ["Implementation"]}], "detection_methods": [{"method": "White Box", "description": "Omission of a break statement might be intentional, in order to support fallthrough. Automated detection methods might therefore be erroneous. Semantic understanding of expected product behavior is re..."}, {"method": "Black Box", "description": "Since this weakness is associated with a code construct, it would be indistinguishable from other errors that produce the same behavior."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C", "C++", "Java", "C#", "PHP", "Not Language-Specific"]}}, "486": {"name": "Comparison of Classes by Name", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product compares classes by name, which can cause it to use the wrong class when multiple classes can have the same name.", "extended_description": "If the decision to trust the methods and data of an object is based on the name of a class, it is possible for malicious users to send objects of the same name as trusted classes and thereby gain the trust afforded to known classes and types.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Use class equivalency to determine type. Rather than use the class name to determine if an object is of a given type, use the getClass() method, and == operator.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "487": {"name": "Reliance on Package-level Scope", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Java packages are not inherently closed; therefore, relying on them for code security is not a good practice.", "extended_description": "The purpose of package scope is to prevent accidental access by other parts of a program. This is an ease-of-software-development feature but not a security feature.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Integrity"], "impact": ["Modify Application Data"]}], "mitigations": [{"description": "Data should be private static and final whenever possible. This will assure that your code is protected by instantiating early, preventing access and tampering.", "phase": ["Architecture and Design", "Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "488": {"name": "Exposure of Data Element to Wrong Session", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not sufficiently enforce boundaries between the states of different sessions, causing data to be provided to, or used by, the wrong session.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Protect the application's sessions from information leakage. Make sure that a session's data is not used or visible by other sessions.", "phase": ["Architecture and Design"]}, {"description": "Use a static analysis tool to scan the code for information leakage vulnerabilities (e.g. Singleton Member Field).", "phase": ["Testing"]}, {"description": "In a multithreading environment, storing user data in Servlet member fields introduces a data access race condition. Do not use member fields to store information in the Servlet.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "489": {"name": "Active Debug Code", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product is released with debugging code still enabled or active.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control", "Other"], "impact": ["Bypass Protection Mechanism", "Read Application Data", "Gain Privileges or Assume Identity", "Varies by Context"]}], "mitigations": [{"description": "Remove debug code before deploying the application.", "phase": ["Build and Compilation", "Distribution"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "ICS/OT"]}}, "49": {"name": "Path Equivalence: 'filename/' (Trailing Slash)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts path input in the form of trailing slash ('filedir/') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "observed_examples": [{"cve": "CVE-2002-0253", "description": "Overlaps infoleak"}, {"cve": "CVE-2001-0446", "description": "Application server allows remote attackers to read source code for .jsp files by appending a / to the requested URL."}, {"cve": "CVE-2004-0334", "description": "Bypass Basic Authentication for files using trailing \"/\""}, {"cve": "CVE-2001-0893", "description": "Read sensitive files with trailing \"/\""}, {"cve": "CVE-2001-0892", "description": "Web server allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "491": {"name": "Public cloneable() Method Without Final ('Object Hijack')", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "A class has a cloneable() method that is not declared final, which allows an object to be created without calling the constructor. This can cause the object to be in an unexpected state.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Unexpected State", "Varies by Context"]}], "mitigations": [{"description": "Make the cloneable() method final.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "492": {"name": "Use of Inner Class Containing Sensitive Data", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Inner classes are translated into classes that are accessible at package scope and may expose code that the programmer intended to keep private to attackers.", "extended_description": "Inner classes quietly introduce several security concerns because of the way they are translated into Java bytecode. In Java source code, it appears that an inner class can be declared to be accessible only by the enclosing class, but Java bytecode has no concept of an inner class, so the compiler must transform an inner class declaration into a peer class with package level access to the original outer class. More insidiously, since an inner class can access private fields in its enclosing clas...", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Using sealed classes protects object-oriented encapsulation paradigms and therefore protects code from being extended in unforeseen ways.", "phase": ["Implementation"]}, {"description": "Inner Classes do not provide security. Warning: Never reduce the security of the object from an outer class, going to an inner class. If an outer class is final or private, ensure that its inner class is private as well.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "493": {"name": "Critical Public Variable Without Final Modifier", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product has a critical public variable that is not final, which allows the variable to be modified to contain unexpected values.", "extended_description": "If a field is non-final and public, it can be changed once the value is set by any function that has access to the class which contains the field. This could lead to a vulnerability if other parts of the program make assumptions about the contents of that field.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Declare all public fields as final when possible, especially if it is used to maintain internal state of an Applet or of classes used by an Applet. If a field must be public, then perform all appropriate sanity checks before accessing the field from your code.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Object-Oriented", "Java", "C++"]}}, "494": {"name": "Download of Code Without Integrity Check", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.", "extended_description": "An attacker can execute malicious code by compromising the host server, performing DNS spoofing, or modifying the code in transit.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Integrity", "Availability", "Confidentiality", "Other"], "impact": ["Execute Unauthorized Code or Commands", "Alter Execution Logic", "Other"]}], "mitigations": [{"description": "Perform proper forward and reverse DNS lookups to detect DNS spoofing.", "phase": ["Implementation"]}, {"description": "Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the s...", "phase": ["Architecture and Design", "Operation"]}], "detection_methods": [{"method": "Manual Analysis"}, {"method": "Black Box"}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2019-9534", "description": "Satellite phone does not validate its firmware image."}, {"cve": "CVE-2021-22909", "description": "Chain: router's firmware update procedure uses curl with \"-k\" (insecure) option that disables certificate validation (CWE-295), allowing adversary-in-..."}, {"cve": "CVE-2008-3438", "description": "OS does not verify authenticity of its own updates."}, {"cve": "CVE-2008-3324", "description": "online poker client does not verify authenticity of its own updates."}, {"cve": "CVE-2001-1125", "description": "anti-virus product does not verify automatic updates for itself."}], "platforms": {"languages": ["Not Language-Specific"]}}, "495": {"name": "Private Data Structure Returned From A Public Method", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product has a method that is declared public, but returns a reference to a private data structure, which could then be modified in unexpected ways.", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}], "mitigations": [{"description": "Declare the method private.", "phase": ["Implementation"]}, {"description": "Clone the member data and keep an unmodified version of the data private to the object.", "phase": ["Implementation"]}, {"description": "Use public setter methods that govern how a private member can be modified.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Object-Oriented", "C", "C++", "Java", "C#"]}}, "496": {"name": "Public Data Assigned to Private Array-Typed Field", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Assigning public data to a private array is equivalent to giving public access to the array.", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}], "mitigations": [{"description": "Do not allow objects to modify private members of a class.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Object-Oriented", "C", "C++", "Java", "C#"]}}, "497": {"name": "Exposure of Sensitive System Information to an Unauthorized Control Sphere", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Production applications should never use methods that generate internal details such as stack traces and error messages unless that information is directly committed to a log that is not viewable by the end user. All error message text should be HTML entity encoded before being written to the log fi...", "phase": ["Architecture and Design", "Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2021-32638", "description": "Code analysis product passes access tokens as a command-line parameter or through an environment variable, making them visible to other processes via ..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "498": {"name": "Cloneable Class Containing Sensitive Information", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The code contains a class with sensitive data, but the class is cloneable. The data can then be accessed by cloning the class.", "extended_description": "Cloneable classes are effectively open classes, since data cannot be hidden in them. Classes that do not explicitly deny cloning can be cloned by any other class without running the constructor.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "If you do make your classes clonable, ensure that your clone method is final and throw super.clone().", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Object-Oriented", "C++", "Java", "C#"]}}, "499": {"name": "Serializable Class Containing Sensitive Data", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The code contains a class with sensitive data, but the class does not explicitly deny serialization. The data can be accessed by serializing the class through another class.", "extended_description": "Serializable classes are effectively open classes since data cannot be hidden in them. Classes that do not explicitly deny serialization can be serialized by any other class, which can then in turn use the data stored inside it.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "In Java, explicitly define final writeObject() to prevent serialization. This is the recommended solution. Define the writeObject() function to throw an exception explicitly denying serialization.", "phase": ["Implementation"]}, {"description": "Make sure to prevent serialization of your objects.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "5": {"name": "J2EE Misconfiguration: Data Transmission Without Encryption", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Information sent over a network can be compromised while in transit. An attacker may be able to read or modify the contents if the data are sent in plaintext or are weakly encrypted.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Integrity"], "impact": ["Modify Application Data"]}], "mitigations": [{"description": "The product configuration should ensure that SSL or an encryption mechanism of equivalent strength and vetted reputation is used for all access-controlled pages.", "phase": ["System Configuration"]}], "platforms": {"languages": ["Java"]}}, "50": {"name": "Path Equivalence: '//multiple/leading/slash'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts path input in the form of multiple leading slash ('//multiple/leading/slash') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "observed_examples": [{"cve": "CVE-2002-1483", "description": "Read files with full pathname using multiple internal slash."}, {"cve": "CVE-1999-1456", "description": "Server allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename."}, {"cve": "CVE-2004-0578", "description": "Server allows remote attackers to read arbitrary files via leading slash (//) characters in a URL request."}, {"cve": "CVE-2002-0275", "description": "Server allows remote attackers to bypass authentication and read restricted files via an extra / (slash) in the requested URL."}, {"cve": "CVE-2004-1032", "description": "Product allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) ch..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "500": {"name": "Public Static Field Not Marked Final", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "An object contains a public static field that is not marked final, which might allow it to be modified in unexpected ways.", "extended_description": "Public static variables can be read without an accessor and changed without a mutator by any classes in the application.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Clearly identify the scope for all critical data elements, including whether they should be regarded as static.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C++", "Java"]}}, "501": {"name": "Trust Boundary Violation", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product mixes trusted and untrusted data in the same data structure or structured message.", "extended_description": "A trust boundary can be thought of as line drawn through a program. On one side of the line, data is untrusted. On the other side of the line, data is assumed to be trustworthy. The purpose of validation logic is to allow data to safely cross the trust boundary - to move from untrusted to trusted. A trust boundary violation occurs when a program blurs the line between what is trusted and what is untrusted. By combining trusted and untrusted data in the same data structure, it becomes easier for ...", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "502": {"name": "Deserialization of Untrusted Data", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data", "Unexpected State"]}, {"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)"]}, {"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "If available, use the signing/sealing features of the programming language to assure that deserialized data has not been tainted. For example, a hash-based message authentication code (HMAC) could be used to ensure that data has not been modified.", "phase": ["Architecture and Design", "Implementation"]}, {"description": "When deserializing data, populate a new object rather than just deserializing. The result is that the data flows through safe input validation and that the functions are safe.", "phase": ["Implementation"]}, {"description": "Explicitly define a final object() to prevent deserialization.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2024-37052", "description": "insecure deserialization in platform for managing AI/ML applications and models allows code execution via a crafted pickled object in a model file"}, {"cve": "CVE-2024-37288", "description": "deserialization of untrusted YAML data in dashboard for data query and visualization of Elasticsearch data"}, {"cve": "CVE-2024-9314", "description": "PHP object injection in WordPress plugin for AI-based SEO"}, {"cve": "CVE-2019-12799", "description": "chain: bypass of untrusted deserialization issue (CWE-502) by using an assumed-trusted class (CWE-183)"}, {"cve": "CVE-2015-8103", "description": "Deserialization issue in commonly-used Java library allows remote execution."}], "platforms": {"languages": ["Java", "Ruby", "PHP", "Python", "JavaScript"], "technologies": ["Not Technology-Specific", "ICS/OT", "AI/ML"]}}, "506": {"name": "Embedded Malicious Code", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product contains code that appears to be malicious in nature.", "extended_description": "Malicious flaws have acquired colorful names, including Trojan horse, trapdoor, timebomb, and logic-bomb. A developer might insert malicious code with the intent to subvert the security of a product or its host system at some time in the future. It generally refers to a program that performs a useful service but exploits rights of the program's user in a way the user does not intend.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Remove the malicious code and start an effort to ensure that no more malicious code exists. This may require a detailed review of all code, as it is possible to hide a serious attack in only one or two lines of code. These lines may be located almost anywhere in an application and may have been inte...", "phase": ["Testing"]}], "detection_methods": [{"method": "Manual Static Analysis - Binary or Bytecode"}, {"method": "Dynamic Analysis with Manual Results Interpretation"}, {"method": "Manual Static Analysis - Source Code"}], "observed_examples": [{"cve": "CVE-2022-30877", "description": "A command history tool was shipped with a code-execution backdoor inserted by a malicious party."}], "platforms": {"languages": ["Not Language-Specific"]}}, "507": {"name": "Trojan Horse", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product appears to contain benign or useful functionality, but it also contains code that is hidden from normal operation that violates the intended security policy of the user or the system administrator.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Most antivirus software scans for Trojan Horses.", "phase": ["Operation"]}, {"description": "Verify the integrity of the product that is being installed.", "phase": ["Installation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "508": {"name": "Non-Replicating Malicious Code", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Non-replicating malicious code only resides on the target system or product that is attacked; it does not attempt to spread to other systems.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Antivirus software can help mitigate known malicious code.", "phase": ["Operation"]}, {"description": "Verify the integrity of the software that is being installed.", "phase": ["Installation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "509": {"name": "Replicating Malicious Code (Virus or Worm)", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Replicating malicious code, including viruses and worms, will attempt to attack other systems once it has successfully compromised the target system or the product.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Antivirus software scans for viruses or worms.", "phase": ["Operation"]}, {"description": "Always verify the integrity of the software that is being installed.", "phase": ["Installation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "51": {"name": "Path Equivalence: '/multiple//internal/slash'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts path input in the form of multiple internal slash ('/multiple//internal/slash/') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-1483", "description": "Read files with full pathname using multiple internal slash."}], "platforms": {"languages": ["Not Language-Specific"]}}, "510": {"name": "Trapdoor", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A trapdoor is a hidden piece of code that responds to a special input, allowing its user access to resources without passing through the normal security enforcement mechanism.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Execute Unauthorized Code or Commands", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Always verify the integrity of the software that is being installed.", "phase": ["Installation"]}, {"description": "Identify and closely inspect the conditions for entering privileged areas of the code, especially those related to authentication, process invocation, and network communications.", "phase": ["Testing"]}], "detection_methods": [{"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Manual Static Analysis - Binary or Bytecode"}, {"method": "Dynamic Analysis with Manual Results Interpretation"}], "platforms": {"languages": ["Not Language-Specific"]}}, "511": {"name": "Logic/Time Bomb", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains code that is designed to disrupt the legitimate operation of the product (or its environment) when a certain time passes, or when a certain logical condition is met.", "extended_description": "When the time bomb or logic bomb is detonated, it may perform a denial of service such as crashing the system, deleting critical data, or degrading system response time. This bomb might be placed within either a replicating or non-replicating Trojan horse.", "consequences": [{"scope": ["Other", "Integrity"], "impact": ["Varies by Context", "Alter Execution Logic"]}], "mitigations": [{"description": "Always verify the integrity of the product that is being installed.", "phase": ["Installation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Conduct a code coverage analysis using live testing, then closely inspect any code that is not covered."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Mobile"]}}, "512": {"name": "Spyware", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product collects personally identifiable information about a human user or the user's activities, but the product accesses this information using other resources besides itself, and it does not require that user's explicit approval or direct input into the product.", "extended_description": "\"Spyware\" is a commonly used term with many definitions and interpretations. In general, it is meant to refer to products that collect information or install functionality that human users might not allow if they were fully aware of the actions being taken by the software. For example, a user might expect that tax software would collect a social security number and include it when filing a tax return, but that same user would not expect gaming software to obtain the social security number from t...", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Use spyware detection and removal software.", "phase": ["Operation"]}, {"description": "Always verify the integrity of the product that is being installed.", "phase": ["Installation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "514": {"name": "Covert Channel", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "A covert channel is a path that can be used to transfer information in a way not intended by the system's designers.", "extended_description": "Typically the system has not given authorization for the transmission and has no knowledge of its occurrence.", "consequences": [{"scope": ["Confidentiality", "Access Control"], "impact": ["Read Application Data", "Bypass Protection Mechanism"]}], "detection_methods": [{"method": "Architecture or Design Review"}], "platforms": {"languages": ["Not Language-Specific"]}}, "515": {"name": "Covert Storage Channel", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A covert storage channel transfers information through the setting of bits by one program and the reading of those bits by another. What distinguishes this case from that of ordinary operation is that the bits are used to convey encoded information.", "extended_description": "Covert storage channels occur when out-of-band data is stored in messages for the purpose of memory reuse. Covert channels are frequently classified as either storage or timing channels. Examples would include using a file intended to hold only audit information to convey user passwords--using the name of a file or perhaps status bits associated with it that can be read by all users to signal the contents of the file. Steganography, concealing information in such a manner that no one but the int...", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Integrity", "Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Ensure that all reserved fields are set to zero before messages are sent and that no unnecessary information is included.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "516": {"name": "DEPRECATED: Covert Timing Channel", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "This weakness can be found at CWE-385."}, "52": {"name": "Path Equivalence: '/multiple/trailing/slash//'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts path input in the form of multiple trailing slash ('/multiple/trailing/slash//') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-1078", "description": "Directory listings in web server using multiple trailing slash"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "520": {"name": ".NET Misconfiguration: Use of Impersonation", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Allowing a .NET application to run at potentially escalated levels of access to the underlying operating and file systems can be dangerous and result in various forms of attacks.", "extended_description": ".NET server applications can optionally execute using the identity of the user authenticated to the client. The intention of this functionality is to bypass authentication and access control checks within the .NET application code. Authentication is done by the underlying web server (Microsoft Internet Information Service IIS), which passes the authenticated token, or unauthenticated anonymous token, to the .NET application. Using the token to impersonate the client, the application then relies ...", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Run the application with limited privilege to the underlying operating and file system.", "phase": ["Operation"]}], "platforms": {"languages": ["Not Language-Specific", "ASP.NET", "VB.NET"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "521": {"name": "Weak Password Requirements", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not require that users should have strong passwords.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Consider a second\n                 authentication factor beyond the password, which prevents the\n                 password from being a single point of failure. See CWE-308 for\n                 further information.", "phase": ["Architecture and Design"]}, {"description": "Consider implementing a password complexity meter to inform users when a chosen password meets the required attributes.", "phase": ["Implementation"]}, {"description": "Previously, \"password expiration\" was\n\t\t\t   widely advocated as a defense-in-depth approach to\n\t\t\t   minimize the risk of weak passwords, and it has become\n\t\t\t   a common practice.  Password expiration requires a\n\t\t\t   password to be changed within a fixed time window (such\n\t\t\t   as every 90 days). ...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2020-4574", "description": "key server application does not require strong passwords"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "522": {"name": "Insufficiently Protected Credentials", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Use an appropriate security mechanism to protect the credentials.", "phase": ["Architecture and Design"]}, {"description": "Make appropriate use of cryptography to protect the credentials.", "phase": ["Architecture and Design"]}, {"description": "Use industry standards to protect the credentials (e.g. LDAP, keystore, etc.).", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-30018", "description": "A messaging platform serializes all elements of User/Group objects, making private information available to adversaries"}, {"cve": "CVE-2022-29959", "description": "Initialization file contains  credentials that can be decoded using a \"simple string transformation\""}, {"cve": "CVE-2022-35411", "description": "Python-based RPC framework enables pickle functionality by default, allowing clients to unpickle untrusted data."}, {"cve": "CVE-2022-29519", "description": "Programmable Logic Controller (PLC) sends sensitive information in plaintext, including passwords and session tokens."}, {"cve": "CVE-2022-30312", "description": "Building Controller uses a protocol that transmits authentication credentials in plaintext."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based", "ICS/OT"]}}, "523": {"name": "Unprotected Transport of Credentials", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Enforce SSL use for the login page or any page used to transmit user credentials or other sensitive information. Even if the entire site does not use SSL, it MUST use SSL for login. Additionally, to help prevent phishing attacks, make sure that SSL serves the login page. SSL allows the user to verif...", "phase": ["Operation", "System Configuration"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "524": {"name": "Use of Cache Containing Sensitive Information", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.", "extended_description": "Applications may use caches to improve efficiency when communicating with remote entities or performing intensive calculations.  A cache maintains a pool of objects, threads, connections, pages, financial data, passwords, or other resources to minimize the time it takes to initialize and access these resources.  If the cache is accessible to unauthorized actors, attackers can read the cache and obtain this sensitive information.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Protect information stored in cache.", "phase": ["Architecture and Design"]}, {"description": "Do not store unnecessarily sensitive information in the cache.", "phase": ["Architecture and Design"]}, {"description": "Consider using encryption in the cache.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "525": {"name": "Use of Web Browser Cache Containing Sensitive Information", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The web application does not use an appropriate caching policy that specifies the extent to which each web page and associated form fields should be cached.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Protect information stored in cache.", "phase": ["Architecture and Design"]}, {"description": "Use a restrictive caching policy for forms and web pages that potentially contain sensitive information.", "phase": ["Architecture and Design", "Implementation"]}, {"description": "Do not store unnecessarily sensitive information in the cache.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "526": {"name": "Cleartext Storage of Sensitive Information in an Environment Variable", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses an environment variable to store unencrypted sensitive information.", "extended_description": "Information stored in an environment variable can be accessible by other processes with the execution context, including child processes that dependencies are executed in, or serverless functions in cloud environments. An environment variable's contents can also be inserted into messages, headers, log files, or other outputs. Often these other dependencies have no need to use the environment variable in question. A weakness that discloses environment variables could expose this information.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Encrypt information stored in the environment variable to protect it from being exposed to an unauthorized user. If encryption is not feasible or is considered too expensive for the business use of the application, then consider using a properly protected configuration file instead of an environment...", "phase": ["Architecture and Design"]}, {"description": "If the environment variable is not necessary for the desired behavior, then remove it entirely, or clear it to an empty value.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-43691", "description": "CMS shows sensitive server-side information from environment variables when run in Debug mode."}, {"cve": "CVE-2022-27195", "description": "Plugin for an automation server inserts environment variable contents into build XML files."}, {"cve": "CVE-2022-25264", "description": "CI/CD tool logs environment variables related to passwords add Contribution to content history."}], "platforms": {"languages": ["Not Language-Specific"]}}, "527": {"name": "Exposure of Version-Control Repository to an Unauthorized Control Sphere", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores a CVS, git, or other repository in a directory, archive, or other resource that is stored, transferred, or otherwise made accessible to unauthorized actors.", "extended_description": "Version control repositories such as CVS or git store version-specific metadata and other details within subdirectories. If these subdirectories are stored on a web server or added to an archive, then these could be used by an attacker. This information may include usernames, filenames, path root, IP addresses, and detailed \"diff\" data about how files have been changed - which could reveal source code snippets that were never intended to be made public.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data", "Read Files or Directories"]}], "mitigations": [{"description": "Recommendations include removing any CVS directories and repositories from the production server, disabling the use of remote CVS repositories, and ensuring that the latest CVS patches and version updates have been performed.", "phase": ["Operation", "Distribution", "System Configuration"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "528": {"name": "Exposure of Core Dump File to an Unauthorized Control Sphere", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product generates a core dump file in a directory, archive, or other resource that is stored, transferred, or otherwise made accessible to unauthorized actors.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data", "Read Files or Directories"]}], "mitigations": [{"description": "Protect the core dump files from unauthorized access.", "phase": ["System Configuration"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "529": {"name": "Exposure of Access Control List Files to an Unauthorized Control Sphere", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores access control list files in a directory or other container that is accessible to actors outside of the intended control sphere.", "extended_description": "Exposure of these access control list files may give the attacker information about the configuration of the site or system. This information may then be used to bypass the intended security policy or identify trusted systems from which an attack can be launched.", "consequences": [{"scope": ["Confidentiality", "Access Control"], "impact": ["Read Application Data", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Protect access control list files.", "phase": ["System Configuration"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "53": {"name": "Path Equivalence: '\\multiple\\\\internal\\backslash'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts path input in the form of multiple internal backslash ('\\multiple\\trailing\\\\slash') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "530": {"name": "Exposure of Backup File to an Unauthorized Control Sphere", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "A backup file is stored in a directory or archive that is made accessible to unauthorized actors.", "extended_description": "Often, older backup files are renamed with an extension such as .~bk to distinguish them from production files. The source code for old files that have been renamed in this manner and left in the webroot can often be retrieved. This renaming may have been performed automatically by the web server, or manually by the administrator.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Recommendations include implementing a security policy within your organization that prohibits backing up web application source code in the webroot.", "phase": ["Policy"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Server"]}}, "531": {"name": "Inclusion of Sensitive Information in Test Code", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Accessible test applications can pose a variety of security risks. Since developers or administrators rarely consider that someone besides themselves would even know about the existence of these applications, it is common for them to contain sensitive information or functions.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Remove test code before deploying the application into production.", "phase": ["Distribution", "Installation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "532": {"name": "Insertion of Sensitive Information into Log File", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product writes sensitive information to a log file.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Consider seriously the sensitivity of the information written into log files. Do not write secrets into the log files.", "phase": ["Architecture and Design", "Implementation"]}, {"description": "Remove debug log files before deploying the application into production.", "phase": ["Distribution"]}, {"description": "Protect log files against unauthorized read/write.", "phase": ["Operation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2017-9615", "description": "verbose logging stores admin credentials in a world-readable log file"}, {"cve": "CVE-2018-1999036", "description": "SSH password for private key stored in build log"}], "platforms": {"languages": ["Not Language-Specific"]}}, "533": {"name": "DEPRECATED: Information Exposure Through Server Log Files", "abstraction": "Variant", "mapping": "PROHIBITED", "structure": "Simple", "description": "This entry has been deprecated because its abstraction was too low-level.  See CWE-532."}, "534": {"name": "DEPRECATED: Information Exposure Through Debug Log Files", "abstraction": "Variant", "mapping": "PROHIBITED", "structure": "Simple", "description": "This entry has been deprecated because its abstraction was too low-level.  See CWE-532."}, "535": {"name": "Exposure of Information Through Shell Error Message", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "A command shell error message indicates that there exists an unhandled exception in the web application code. In many cases, an attacker can leverage the conditions that cause these errors in order to gain unauthorized access to the system.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "536": {"name": "Servlet Runtime Error Message Containing Sensitive Information", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "A servlet error message indicates that there exists an unhandled exception in the web application code and may provide useful information to an attacker.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "platforms": {"languages": ["Java"], "technologies": ["Web Based", "Web Server"]}}, "537": {"name": "Java Runtime Error Message Containing Sensitive Information", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "In many cases, an attacker can leverage the conditions that cause unhandled exception errors in order to gain unauthorized access to the system.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Do not expose sensitive error information to the user.", "phase": ["Implementation"]}], "platforms": {"languages": ["Java"]}}, "538": {"name": "Insertion of Sensitive Information into Externally-Accessible File or Directory", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Files or Directories"]}], "mitigations": [{"description": "Do not expose file and directory information to the user.", "phase": ["Architecture and Design", "Operation", "System Configuration"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2018-1999036", "description": "SSH password for private key stored in build log"}], "platforms": {"languages": ["Not Language-Specific"]}}, "539": {"name": "Use of Persistent Cookies Containing Sensitive Information", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The web application uses persistent cookies, but the cookies contain sensitive information.", "extended_description": "Cookies are small bits of data that are sent by the web application but stored locally in the browser. This lets the application use the cookie to pass information between pages and store variable information. The web application controls what information is stored in a cookie and how it is used. Typical types of information stored in cookies are session identifiers, personalization and customization information, and in rare cases even usernames to enable automated logins. There are two differen...", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Do not store sensitive information in persistent cookies.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "54": {"name": "Path Equivalence: 'filedir\\' (Trailing Backslash)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts path input in the form of trailing backslash ('filedir\\') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2004-0847", "description": "web framework for .NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) \"\\\" (..."}, {"cve": "CVE-2004-0061", "description": "Bypass directory access restrictions using trailing dot in URL"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "540": {"name": "Inclusion of Sensitive Information in Source Code", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "Source code on a web server or repository often contains sensitive information and should generally not be accessible to users.", "extended_description": "There are situations where it is critical to remove source code from an area or server. For example, obtaining Perl source code on a system allows an attacker to understand the logic of the script and extract extremely useful information such as code bugs or logins and passwords.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Recommendations include removing this script from the web server and moving it to a location not accessible from the Internet.", "phase": ["Architecture and Design", "System Configuration"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-25512", "description": "Server for Team Awareness Kit (TAK) application includes sensitive tokens in the JavaScript source code."}, {"cve": "CVE-2022-24867", "description": "The LDAP password might be visible in the html code of a rendered page in an IT Asset Management tool."}, {"cve": "CVE-2007-6197", "description": "Version numbers and internal hostnames leaked in HTML comments."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "541": {"name": "Inclusion of Sensitive Information in an Include File", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "If an include file source is accessible, the file can contain usernames and passwords, as well as sensitive information pertaining to the application and system.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Do not store sensitive information in include files.", "phase": ["Architecture and Design"]}, {"description": "Protect include files from being exposed.", "phase": ["Architecture and Design", "System Configuration"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "542": {"name": "DEPRECATED: Information Exposure Through Cleanup Log Files", "abstraction": "Variant", "mapping": "PROHIBITED", "structure": "Simple", "description": "This entry has been deprecated because its abstraction was too low-level.  See CWE-532."}, "543": {"name": "Use of Singleton Pattern Without Synchronization in a Multithreaded Context", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses the singleton pattern when creating a resource within a multithreaded environment.", "extended_description": "The use of a singleton pattern may not be thread-safe.", "consequences": [{"scope": ["Other", "Integrity"], "impact": ["Other", "Modify Application Data"]}], "mitigations": [{"description": "Use the Thread-Specific Storage Pattern. See References.", "phase": ["Architecture and Design"]}, {"description": "Do not use member fields to store information in the Servlet. In multithreading environments, storing user data in Servlet member fields introduces a data access race condition.", "phase": ["Implementation"]}, {"description": "Avoid using the double-checked locking pattern in language versions that cannot guarantee thread safety. This pattern may be used to avoid the overhead of a synchronized call, but in certain versions of Java (for example), this has been shown to be unsafe because it still introduces a race condition...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java", "C++"]}}, "544": {"name": "Missing Standardized Error Handling Mechanism", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not use a standardized method for handling errors throughout the code, which might introduce inconsistent error handling and resultant weaknesses.", "extended_description": "If the product handles error messages individually, on a one-by-one basis, this is likely to result in inconsistent error handling. The causes of errors may be lost. Also, detailed information about the causes of an error may be unintentionally returned to the user.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Quality Degradation", "Unexpected State", "Varies by Context"]}], "mitigations": [{"description": "define a strategy for handling errors of different severities, such as fatal errors versus basic log events. Use or create built-in language features, or an external package, that provides an easy-to-use API and define coding standards for the detection and handling of errors.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "545": {"name": "DEPRECATED: Use of Dynamic Class Loading", "abstraction": "Variant", "mapping": "PROHIBITED", "structure": "Simple", "description": "This weakness has been deprecated because it partially overlaps CWE-470, it describes legitimate programmer behavior, and other portions will need to be integrated into other entries."}, "546": {"name": "Suspicious Comment", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The code contains comments that suggest the presence of bugs, incomplete functionality, or weaknesses.", "extended_description": "Many suspicious comments, such as BUG, HACK, FIXME, LATER, LATER2, TODO, in the code indicate missing security functionality and checking. Others indicate code problems that programmers should fix, such as hard-coded variables, error handling, not using stored procedures, and performance issues.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "mitigations": [{"description": "Remove comments that suggest the presence of bugs, incomplete functionality, or weaknesses, before deploying the application.", "phase": ["Documentation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "547": {"name": "Use of Hard-coded, Security-relevant Constants", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses hard-coded constants instead of symbolic names for security-critical values, which increases the likelihood of mistakes during code maintenance or security policy change.", "extended_description": "If the developer does not find all occurrences of the hard-coded constants, an incorrect policy decision may be made if one of the constants is not changed. Making changes to these values will require code changes that may be difficult or impossible once the system is released to the field. In addition, these hard-coded values may become available to attackers if the code is ever disclosed.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context", "Quality Degradation", "Reduce Maintainability"]}], "mitigations": [{"description": "Avoid using hard-coded constants. Configuration files offer a more flexible solution.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "548": {"name": "Exposure of Information Through Directory Listing", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Files or Directories"]}], "mitigations": [{"description": "Recommendations include restricting access to important directories or files by adopting a need to know requirement for both the document and server root, and turning off features such as Automatic Directory Listings that could expose private files and provide information that could be utilized by a...", "phase": ["Architecture and Design", "System Configuration"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "549": {"name": "Missing Password Field Masking", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not mask passwords during entry, increasing the potential for attackers to observe and capture passwords.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Recommendations include requiring all password fields in your web application be masked to prevent other users from seeing this information.", "phase": ["Implementation", "Requirements"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "55": {"name": "Path Equivalence: '/./' (Single Dot Directory)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts path input in the form of single dot directory exploit ('/./') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2024-6091", "description": "Chain: AI agent platform does not restrict pathnames containing internal \"/./\" sequences (CWE-55), leading to an incomplete denylist (CWE-184) that do..."}, {"cve": "CVE-2000-0004", "description": "Server allows remote attackers to read source code for executable files by inserting a . (dot) into the URL."}, {"cve": "CVE-2002-0304", "description": "Server allows remote attackers to read password-protected files via a /./ in the HTTP request."}, {"cve": "CVE-1999-1083", "description": "Possibly (could be a cleansing error)"}, {"cve": "CVE-2004-0815", "description": "\"/./////etc\" cleansed to \".///etc\" then \"/etc\""}], "platforms": {"languages": ["Not Language-Specific"]}}, "550": {"name": "Server-generated Error Message Containing Sensitive Information", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Certain conditions, such as network failure, will cause a server error message to be displayed.", "extended_description": "While error messages in and of themselves are not dangerous, per se, it is what an attacker can glean from them that might cause eventual problems.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Recommendations include designing and adding consistent error handling mechanisms which are capable of handling any user input to your web application, providing meaningful detail to end-users, and preventing error messages that might provide information useful to an attacker from being displayed.", "phase": ["Architecture and Design", "System Configuration"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "551": {"name": "Incorrect Behavior Order: Authorization Before Parsing and Canonicalization", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "If a web server does not fully parse requested URLs before it examines them for authorization, it may be possible for an attacker to bypass authorization protection.", "extended_description": "For instance, the character strings /./ and / both mean current directory. If /SomeDirectory is a protected directory and an attacker requests /./SomeDirectory, the attacker may be able to gain access to the resource if /./ is not converted to / before the authorization check is performed.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "URL Inputs should be decoded and canonicalized to the application's current internal representation before being validated and processed for authorization. Make sure that your application does not decode the same input twice. Such errors could be used to bypass allowlist schemes by introducing dange...", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based", "Web Server"]}}, "552": {"name": "Files or Directories Accessible to External Parties", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product makes files or directories accessible to unauthorized actors, even though they should not be.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to disable public access.", "phase": ["Implementation", "System Configuration", "Operation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2005-1835", "description": "Data file under web root."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Cloud Computing"]}}, "553": {"name": "Command Shell in Externally Accessible Directory", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "A possible shell file exists in /cgi-bin/ or other accessible directories. This is extremely dangerous and can be used by an attacker to execute commands on the web server.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Remove any Shells accessible under the web root folder and children directories.", "phase": ["Installation", "System Configuration"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "554": {"name": "ASP.NET Misconfiguration: Not Using Input Validation Framework", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The ASP.NET application does not use an input validation framework.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "platforms": {"languages": ["ASP.NET"]}}, "555": {"name": "J2EE Misconfiguration: Plaintext Password in Configuration File", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The J2EE application stores a plaintext password in a configuration file.", "extended_description": "Storing a plaintext password in a configuration file allows anyone who can read the file to access the password-protected resource, making it an easy target for attackers.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Do not hardwire passwords into your software.", "phase": ["Architecture and Design"]}, {"description": "Use industry standard libraries to encrypt passwords before storage in configuration files.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Java"]}}, "556": {"name": "ASP.NET Misconfiguration: Use of Identity Impersonation", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Configuring an ASP.NET application to run with impersonated credentials may give the application unnecessary privileges.", "extended_description": "The use of impersonated credentials allows an ASP.NET application to run with either the privileges of the client on whose behalf it is executing or with arbitrary privileges granted in its configuration.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Use the least privilege principle.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["ASP.NET"]}}, "558": {"name": "Use of getlogin() in Multithreaded Application", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses the getlogin() function in a multithreaded context, potentially causing it to return incorrect values.", "extended_description": "The getlogin() function returns a pointer to a string that contains the name of the user associated with the calling process. The function is not reentrant, meaning that if it is called from another process, the contents are not locked out and the value of the string can be changed by another process. This makes it very risky to use because the username can be changed by other processes, so the results of the function cannot be trusted.", "consequences": [{"scope": ["Integrity", "Access Control", "Other"], "impact": ["Modify Application Data", "Bypass Protection Mechanism", "Other"]}], "mitigations": [{"description": "Using names for security purposes is not advised. Names are easy to forge and can have overlapping user IDs, potentially causing confusion or impersonation.", "phase": ["Architecture and Design"]}, {"description": "Use getlogin_r() instead, which is reentrant, meaning that other processes are locked out from changing the username.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C", "C++"]}}, "56": {"name": "Path Equivalence: 'filedir*' (Wildcard)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accepts path input in the form of asterisk wildcard ('filedir*') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2004-0696", "description": "List directories using desired path and \"*\""}, {"cve": "CVE-2002-0433", "description": "List files in web server using \"*.ext\""}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "560": {"name": "Use of umask() with chmod-style Argument", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product calls umask() with an incorrect argument that is specified as if it is an argument to chmod().", "consequences": [{"scope": ["Confidentiality", "Integrity", "Access Control"], "impact": ["Read Files or Directories", "Modify Files or Directories", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Use umask() with the correct argument.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "If you suspect misuse of umask(), you can use grep to spot call instances of umask()."}], "platforms": {"languages": ["C"]}}, "561": {"name": "Dead Code", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains dead code, which can never be executed.", "extended_description": "Dead code is code that can never be executed in a running program. The surrounding code makes it impossible for a section of code to ever be executed.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}, {"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "mitigations": [{"description": "Remove dead code before deploying the application.", "phase": ["Implementation"]}, {"description": "Use a static analysis tool to spot dead code.", "phase": ["Testing"]}], "detection_methods": [{"method": "Architecture or Design Review"}, {"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Dynamic Analysis with Manual Results Interpretation"}], "observed_examples": [{"cve": "CVE-2014-1266", "description": "Chain: incorrect \"goto\" in Apple SSL product bypasses certificate validation, allowing Adversary-in-the-Middle (AITM) attack (Apple \"goto fail\" bug). ..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "562": {"name": "Return of Stack Variable Address", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A function returns the address of a stack variable, which will cause unintended program behavior, typically in the form of a crash.", "extended_description": "Because local variables are allocated on the stack, when a program returns a pointer to a local variable, it is returning a stack address. A subsequent function call is likely to re-use this same stack address, thereby overwriting the value of the pointer, which no longer corresponds to the same variable since a function's stack frame is invalidated when it returns. At best this will cause the value of the pointer to change unexpectedly. In many cases it causes the program to crash the next time...", "consequences": [{"scope": ["Availability", "Integrity", "Confidentiality"], "impact": ["Read Memory", "Modify Memory", "Execute Unauthorized Code or Commands", "DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Use static analysis tools to spot return of the address of a stack variable.", "phase": ["Testing"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2024-33045", "description": "product returns stack variable address, leading to memory corruption"}], "platforms": {"languages": ["C", "C++"]}}, "563": {"name": "Assignment to Variable without Use", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The variable's value is assigned but never used, making it a dead store.", "extended_description": "After the assignment, the variable is either assigned another value or goes out of scope. It is likely that the variable is simply vestigial, but it is also possible that the unused variable points out a bug.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation", "Varies by Context"]}], "mitigations": [{"description": "Remove unused variables from the code.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "564": {"name": "SQL Injection: Hibernate", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Using Hibernate to execute a dynamic SQL statement built with user-controlled input can allow an attacker to modify the statement's meaning or to execute arbitrary SQL commands.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data"]}], "mitigations": [{"description": "A non-SQL style database which is not subject to this flaw may be chosen.", "phase": ["Requirements"]}, {"description": "Follow the principle of least privilege when creating user accounts to a SQL database. Users should only have the minimum privileges necessary to use their account. If the requirements of the system indicate that a user can read and modify their own data, then limit their privileges so they cannot r...", "phase": ["Architecture and Design"]}, {"description": "For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-s...", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["SQL"], "technologies": ["Database Server"]}}, "565": {"name": "Reliance on Cookies without Validation and Integrity Checking", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Modify Application Data", "Execute Unauthorized Code or Commands"]}, {"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Avoid using cookie data for a security-related decision.", "phase": ["Architecture and Design"]}, {"description": "Perform thorough input validation (i.e.: server side validation) on the cookie data if you're going to use it for a security related decision.", "phase": ["Implementation"]}, {"description": "Add integrity checks to detect tampering.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2008-5784", "description": "e-dating application allows admin privileges by setting the admin cookie to 1."}], "platforms": {"languages": ["Not Language-Specific"]}}, "566": {"name": "Authorization Bypass Through User-Controlled SQL Primary Key", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a database table that includes records that should not be accessible to an actor, but it executes a SQL statement with a primary key that can be controlled by that actor.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Access Control"], "impact": ["Read Application Data", "Modify Application Data", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Assume all input is malicious. Use a standard input validation mechanism to validate all input for length, type, syntax, and business rules before accepting the data. Use an \"accept known good\" validation strategy.", "phase": ["Implementation"]}, {"description": "Use a parameterized query AND make sure that the accepted values conform to the business rules. Construct your SQL statement accordingly.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["SQL"], "technologies": ["Database Server"]}}, "567": {"name": "Unsynchronized Access to Shared Data in a Multithreaded Context", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly synchronize shared data, such as static variables across threads, which can lead to undefined behavior and unpredictable data changes.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Read Application Data", "Modify Application Data", "DoS: Instability", "DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Remove the use of static variables used between servlets. If this cannot be avoided, use synchronized access for these variables.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "568": {"name": "finalize() Method Without super.finalize()", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains a finalize() method that does not call super.finalize().", "extended_description": "The Java Language Specification states that it is a good practice for a finalize() method to call super.finalize().", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "mitigations": [{"description": "Call the super.finalize() method.", "phase": ["Implementation"]}, {"description": "Use static analysis tools to spot such issues in your code.", "phase": ["Testing"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "57": {"name": "Path Equivalence: 'fakedir/../realdir/filename'", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains protection mechanisms to restrict access to 'realdir/filename', but it constructs pathnames using external input in the form of 'fakedir/../realdir/filename' that are not handled by those mechanisms. This allows attackers to perform unauthorized actions against the targeted file.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous i...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2001-1152", "description": "Proxy allows remote attackers to bypass denylist restrictions and connect to unauthorized web servers by modifying the requested URL, including (1) a ..."}, {"cve": "CVE-2000-0191", "description": "application check access for restricted URL before canonicalization"}, {"cve": "CVE-2005-1366", "description": "CGI source disclosure using \"dirname/../cgi-bin\""}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "570": {"name": "Expression is Always False", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains an expression that will always evaluate to false.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation", "Varies by Context"]}], "mitigations": [{"description": "Use Static Analysis tools to spot such conditions.", "phase": ["Testing"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "571": {"name": "Expression is Always True", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains an expression that will always evaluate to true.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation", "Varies by Context"]}], "mitigations": [{"description": "Use Static Analysis tools to spot such conditions.", "phase": ["Testing"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "572": {"name": "Call to Thread run() instead of start()", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product calls a thread's run() method instead of calling start(), which causes the code to run in the thread of the caller instead of the callee.", "extended_description": "In most cases a direct call to a Thread object's run() method is a bug. The programmer intended to begin a new thread of control, but accidentally called run() instead of start(), so the run() method will execute in the caller's thread of control.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation", "Varies by Context"]}], "mitigations": [{"description": "Use the start() method instead of the run() method.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "573": {"name": "Improper Following of Specification by Caller", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not follow or incorrectly follows the specifications as required by the implementation language, environment, framework, protocol, or platform.", "extended_description": "When leveraging external functionality, such as an API, it is important that the caller does so in accordance with the requirements of the external functionality or else unintended behaviors may result, possibly leaving the system vulnerable to any number of exploits.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation", "Varies by Context"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2006-7140", "description": "Crypto implementation removes padding when it shouldn't, allowing forged signatures"}, {"cve": "CVE-2006-4339", "description": "Crypto implementation removes padding when it shouldn't, allowing forged signatures"}], "platforms": {"languages": ["Not Language-Specific"]}}, "574": {"name": "EJB Bad Practices: Use of Synchronization Primitives", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product violates the Enterprise JavaBeans (EJB) specification by using thread synchronization primitives.", "extended_description": "The Enterprise JavaBeans specification requires that every bean provider follow a set of programming guidelines designed to ensure that the bean will be portable and behave consistently in any EJB container. In this case, the product violates the following EJB guideline: \"An enterprise bean must not use thread synchronization primitives to synchronize execution of multiple instances.\" The specification justifies this requirement in the following way: \"This rule is required to ensure consistent r...", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "mitigations": [{"description": "Do not use Synchronization Primitives when writing EJBs.", "phase": ["Implementation"]}], "platforms": {"languages": ["Java"]}}, "575": {"name": "EJB Bad Practices: Use of AWT Swing", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product violates the Enterprise JavaBeans (EJB) specification by using AWT/Swing.", "extended_description": "The Enterprise JavaBeans specification requires that every bean provider follow a set of programming guidelines designed to ensure that the bean will be portable and behave consistently in any EJB container. In this case, the product violates the following EJB guideline: \"An enterprise bean must not use the AWT functionality to attempt to output information to a display, or to input information from a keyboard.\" The specification justifies this requirement in the following way: \"Most servers do ...", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "mitigations": [{"description": "Do not use AWT/Swing when writing EJBs.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Java"]}}, "576": {"name": "EJB Bad Practices: Use of Java I/O", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product violates the Enterprise JavaBeans (EJB) specification by using the java.io package.", "extended_description": "The Enterprise JavaBeans specification requires that every bean provider follow a set of programming guidelines designed to ensure that the bean will be portable and behave consistently in any EJB container. In this case, the product violates the following EJB guideline: \"An enterprise bean must not use the java.io package to attempt to access files and directories in the file system.\" The specification justifies this requirement in the following way: \"The file system APIs are not well-suited fo...", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "mitigations": [{"description": "Do not use Java I/O when writing EJBs.", "phase": ["Implementation"]}], "platforms": {"languages": ["Java"]}}, "577": {"name": "EJB Bad Practices: Use of Sockets", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product violates the Enterprise JavaBeans (EJB) specification by using sockets.", "extended_description": "The Enterprise JavaBeans specification requires that every bean provider follow a set of programming guidelines designed to ensure that the bean will be portable and behave consistently in any EJB container. In this case, the product violates the following EJB guideline: \"An enterprise bean must not attempt to listen on a socket, accept connections on a socket, or use a socket for multicast.\" The specification justifies this requirement in the following way: \"The EJB architecture allows an enter...", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "mitigations": [{"description": "Do not use Sockets when writing EJBs.", "phase": ["Architecture and Design", "Implementation"]}], "platforms": {"languages": ["Java"]}}, "578": {"name": "EJB Bad Practices: Use of Class Loader", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product violates the Enterprise JavaBeans (EJB) specification by using the class loader.", "extended_description": "The Enterprise JavaBeans specification requires that every bean provider follow a set of programming guidelines designed to ensure that the bean will be portable and behave consistently in any EJB container. In this case, the product violates the following EJB guideline: \"The enterprise bean must not attempt to create a class loader; obtain the current class loader; set the context class loader; set security manager; create a new security manager; stop the JVM; or change the input, output, and e...", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Other"], "impact": ["Execute Unauthorized Code or Commands", "Varies by Context"]}], "mitigations": [{"description": "Do not use the Class Loader when writing EJBs.", "phase": ["Architecture and Design", "Implementation"]}], "platforms": {"languages": ["Java"]}}, "579": {"name": "J2EE Bad Practices: Non-serializable Object Stored in Session", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores a non-serializable object as an HttpSession attribute, which can hurt reliability.", "extended_description": "A J2EE application can make use of multiple JVMs in order to improve application reliability and performance. In order to make the multiple JVMs appear as a single application to the end user, the J2EE container can replicate an HttpSession object across multiple JVMs so that if one JVM becomes unavailable another can step in and take its place without disrupting the flow of the application. This is only possible if all session data is serializable, allowing the session to be duplicated between ...", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "mitigations": [{"description": "In order for session replication to work, the values the product stores as attributes in the session must implement the Serializable interface.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "58": {"name": "Path Equivalence: Windows 8.3 Filename", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains a protection mechanism that restricts access to a long filename on a Windows operating system, but it does not properly restrict access to the equivalent short \"8.3\" filename.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Disable Windows from supporting 8.3 filenames by editing the Windows registry. Preventing 8.3 filenames will not remove previously generated 8.3 filenames.", "phase": ["System Configuration"]}], "observed_examples": [{"cve": "CVE-1999-0012", "description": "Multiple web servers allow restriction bypass using 8.3 names instead of long names"}, {"cve": "CVE-2001-0795", "description": "Source code disclosure using 8.3 file name."}, {"cve": "CVE-2005-0471", "description": "Multi-Factor Vulnerability. Product generates temporary filenames using long filenames, which become predictable in 8.3 format."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "580": {"name": "clone() Method Without super.clone()", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains a clone() method that does not call super.clone() to obtain the new object.", "extended_description": "All implementations of clone() should obtain the new object by calling super.clone(). If a class does not follow this convention, a subclass's clone() method will return an object of the wrong type.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Unexpected State", "Quality Degradation"]}], "mitigations": [{"description": "Call super.clone() within your clone() method, when obtaining a new object.", "phase": ["Implementation"]}, {"description": "In some cases, you can eliminate the clone method altogether and use copy constructors.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "581": {"name": "Object Model Violation: Just One of Equals and Hashcode Defined", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not maintain equal hashcodes for equal objects.", "extended_description": "Java objects are expected to obey a number of invariants related to equality. One of these invariants is that equal objects must have equal hashcodes. In other words, if a.equals(b) == true then a.hashCode() == b.hashCode().", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Other"]}], "mitigations": [{"description": "Both Equals() and Hashcode() should be defined.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "582": {"name": "Array Declared Public, Final, and Static", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product declares an array public, final, and static, which is not sufficient to prevent the array's contents from being modified.", "extended_description": "Because arrays are mutable objects, the final constraint requires that the array object itself be assigned only once, but makes no guarantees about the values of the array elements. Since the array is public, a malicious program can change the values stored in the array. As such, in most cases an array declared public, final and static is a bug.", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}], "mitigations": [{"description": "In most situations the array should be made private.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "583": {"name": "finalize() Method Declared Public", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product violates secure coding principles for mobile code by declaring a finalize() method public.", "extended_description": "A product should never call finalize explicitly, except to call super.finalize() inside an implementation of finalize(). In mobile code situations, the otherwise error prone practice of manual garbage collection can become a security threat if an attacker can maliciously invoke a finalize() method because it is declared with public access.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Alter Execution Logic", "Execute Unauthorized Code or Commands", "Modify Application Data"]}], "mitigations": [{"description": "If you are using finalize() as it was designed, there is no reason to declare finalize() with anything other than protected access.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "584": {"name": "Return Inside Finally Block", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The code has a return statement inside a finally block, which will cause any thrown exception in the try block to be discarded.", "consequences": [{"scope": ["Other"], "impact": ["Alter Execution Logic"]}], "mitigations": [{"description": "Do not use a return statement inside the finally block. The finally block should have \"cleanup\" code.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "585": {"name": "Empty Synchronized Block", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains an empty synchronized block.", "extended_description": "An empty synchronized block does not actually accomplish any synchronization and may indicate a troubled section of code. An empty synchronized block can occur because code no longer needed within the synchronized block is commented out without removing the synchronized block.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "mitigations": [{"description": "When you come across an empty synchronized statement, or a synchronized statement in which the code has been commented out, try to determine what the original intentions were and whether or not the synchronized block is still necessary.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "586": {"name": "Explicit Call to Finalize()", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product makes an explicit call to the finalize() method from outside the finalizer.", "extended_description": "While the Java Language Specification allows an object's finalize() method to be called from outside the finalizer, doing so is usually a bad idea. For example, calling finalize() explicitly means that finalize() will be called more than once: the first time will be the explicit call and the last time will be the call that is made after the object is garbage collected.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Unexpected State", "Quality Degradation"]}], "mitigations": [{"description": "Do not make explicit calls to finalize(). Use static analysis tools to spot such instances.", "phase": ["Implementation", "Testing"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "587": {"name": "Assignment of a Fixed Address to a Pointer", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product sets a pointer to a specific address other than NULL or 0.", "extended_description": "Using a fixed address is not portable, because that address will probably not be valid in all environments or platforms.", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart", "Reduce Maintainability", "Reduce Reliability"]}, {"scope": ["Confidentiality", "Integrity"], "impact": ["Read Memory", "Modify Memory"]}], "mitigations": [{"description": "Never set a pointer to a fixed address.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++", "C#", "Assembly"]}}, "588": {"name": "Attempt to Access Child of a Non-structure Pointer", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "Casting a non-structure type to a structure type and accessing a field can lead to memory access errors or data corruption.", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Memory"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "The choice could be made to use a language that is not susceptible to these issues.", "phase": ["Requirements"]}, {"description": "Review of type casting operations can identify locations where incompatible types are cast.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2021-3510", "description": "JSON decoder accesses a C union using an invalid offset to an object"}], "platforms": {"languages": ["C", "C++"]}}, "589": {"name": "Call to Non-ubiquitous API", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses an API function that does not exist on all versions of the target platform. This could cause portability problems or inconsistencies that allow denial of service or other consequences.", "extended_description": "Some functions that offer security features supported by the OS are not available on all versions of the OS in common use. Likewise, functions are often deprecated or made obsolete for security reasons and should not be used.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "mitigations": [{"description": "Always test your code on any platform on which it is targeted to run on.", "phase": ["Implementation"]}, {"description": "Test your code on the newest and oldest platform on which it is targeted to run on.", "phase": ["Testing"]}, {"description": "Develop a system to test for API functions that are not portable.", "phase": ["Testing"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "59": {"name": "Improper Link Resolution Before File Access ('Link Following')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality", "Integrity", "Access Control"], "impact": ["Read Files or Directories", "Modify Files or Directories", "Bypass Protection Mechanism"]}, {"scope": ["Other"], "impact": ["Execute Unauthorized Code or Commands"]}], "detection_methods": [{"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Manual Static Analysis - Binary or Bytecode"}, {"method": "Dynamic Analysis with Automated Results Interpretation"}], "observed_examples": [{"cve": "CVE-1999-1386", "description": "Some versions of Perl follow symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attac..."}, {"cve": "CVE-2000-1178", "description": "Text editor follows symbolic links when creating a rescue copy during an abnormal exit, which allows local users to overwrite the files of other users..."}, {"cve": "CVE-2004-0217", "description": "Antivirus update allows local users to create or append to arbitrary files via a symlink attack on a logfile."}, {"cve": "CVE-2003-0517", "description": "Symlink attack allows local users to overwrite files."}, {"cve": "CVE-2004-0689", "description": "Window manager does not properly handle when certain symbolic links point to \"stale\" locations, which could allow local users to create or truncate ar..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "590": {"name": "Free of Memory not on the Heap", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product calls free() on a pointer to memory that was not allocated using associated heap allocation functions such as malloc(), calloc(), or realloc().", "extended_description": "When free() is called on an invalid pointer, the program's memory management data structures may become corrupted. This corruption can cause the program to crash or, in some circumstances, an attacker may be able to cause free() to operate on controllable memory locations to modify critical program variables or execute code.", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands", "Modify Memory"]}], "mitigations": [{"description": "Only free pointers that you have called malloc on previously. This is the recommended solution. Keep track of which pointers point at the beginning of valid chunks and free them only once.", "phase": ["Implementation"]}, {"description": "Before freeing a pointer, the programmer should make sure that the pointer was previously allocated on the heap and that the memory belongs to the programmer. Freeing an unallocated pointer will cause undefined behavior in the program.", "phase": ["Implementation"]}, {"description": "Use a language that provides abstractions for memory allocation and deallocation.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "platforms": {"languages": ["Memory-Unsafe", "C"]}}, "591": {"name": "Sensitive Data Storage in Improperly Locked Memory", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores sensitive data in memory that is not locked, or that has been incorrectly locked, which might cause the memory to be written to swap files on disk by the virtual memory manager. This can make the data more accessible to external actors.", "extended_description": "On Windows systems the VirtualLock function can lock a page of memory to ensure that it will remain present in memory and not be swapped to disk. However, on older versions of Windows, such as 95, 98, or Me, the VirtualLock() function is only a stub and provides no protection. On POSIX systems the mlock() call ensures that a page will stay resident in memory but does not guarantee that the page will not appear in the swap. Therefore, it is unsuitable for use as a protection mechanism for sensiti...", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data", "Read Memory"]}], "mitigations": [{"description": "Identify data that needs to be protected from swapping and choose platform-appropriate protection mechanisms.", "phase": ["Architecture and Design"]}, {"description": "Check return values to ensure locking operations are successful.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "592": {"name": "DEPRECATED: Authentication Bypass Issues", "abstraction": "Class", "mapping": "PROHIBITED", "structure": "Simple", "description": "This weakness has been deprecated because it covered redundant concepts already described in CWE-287."}, "593": {"name": "Authentication Bypass: OpenSSL CTX Object Modified after SSL Objects are Created", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product modifies the SSL context after connection creation has begun.", "extended_description": "If the program modifies the SSL_CTX object after creating SSL objects from it, there is the possibility that older SSL objects created from the original context could all be affected by that change.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Use a language or a library that provides a cryptography framework at a higher level of abstraction.", "phase": ["Architecture and Design"]}, {"description": "Most SSL_CTX functions have SSL counterparts that act on SSL-type objects.", "phase": ["Implementation"]}, {"description": "Applications should set up an SSL_CTX completely, before creating SSL objects from it.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "594": {"name": "J2EE Framework: Saving Unserializable Objects to Disk", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "When the J2EE container attempts to write unserializable objects to disk there is no guarantee that the process will complete successfully.", "extended_description": "In heavy load conditions, most J2EE application frameworks flush objects to disk to manage memory requirements of incoming requests. For example, session scoped objects, and even application scoped objects, are written to disk when required. While these application frameworks do the real work of writing objects to disk, they do not enforce that those objects be serializable, thus leaving the web application vulnerable to crashes induced by serialization failure. An attacker may be able to mount ...", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "All objects that become part of session and application scope must implement the java.io.Serializable interface to ensure serializability of containing objects.", "phase": ["Architecture and Design", "Implementation"]}], "platforms": {"languages": ["Java"], "technologies": ["Web Based", "Web Server"]}}, "595": {"name": "Comparison of Object References Instead of Object Contents", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product compares object references instead of the contents of the objects themselves, preventing it from detecting equivalent objects.", "extended_description": "For example, in Java, comparing objects using == usually produces deceptive results, since the == operator compares object references rather than values; often, this means that using == for strings is actually comparing the strings' references, not their values.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "In Java, use the equals() method to compare objects instead of the == operator. If using ==, it is important for performance reasons that your objects are created by a static factory, not by a constructor.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java", "JavaScript", "PHP", "Not Language-Specific"]}}, "596": {"name": "DEPRECATED: Incorrect Semantic Object Comparison", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "This weakness has been deprecated.  It was poorly described and difficult to distinguish from other entries.  It was also inappropriate to assign a separate ID solely because of domain-specific considerations.  Its closest equivalent is CWE-1023."}, "597": {"name": "Use of Wrong Operator in String Comparison", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses the wrong operator when comparing a string, such as using \"==\" when the .equals() method should be used instead.", "extended_description": "In Java, using == or != to compare two strings for equality actually compares two objects for equality rather than their string values for equality. Chances are good that the two references will never be equal. While this weakness often only affects program correctness, if the equality is used for a security decision, the unintended comparison result could be leveraged to affect program security.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "mitigations": [{"description": "Within Java, use .equals() to compare string values.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific", "Java", "JavaScript", "PHP"]}}, "598": {"name": "Use of GET Request Method With Sensitive Query Strings", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "When sensitive information is sent, use the POST method (e.g. registration form).", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-23546", "description": "A discussion platform leaks private information in GET requests."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "599": {"name": "Missing Validation of OpenSSL Certificate", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses OpenSSL and trusts or uses a certificate without using the SSL_get_verify_result() function to ensure that the certificate satisfies all necessary security requirements.", "extended_description": "This could allow an attacker to use an invalid certificate to claim to be a trusted host, use expired certificates, or conduct other attacks that could be detected if the certificate is properly validated.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}, {"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Ensure that proper authentication is included in the system design.", "phase": ["Architecture and Design"]}, {"description": "Understand and properly implement all checks necessary to ensure the identity of entities involved in encrypted communications.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "6": {"name": "J2EE Misconfiguration: Insufficient Session-ID Length", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The J2EE application is configured to use an insufficient session ID length.", "extended_description": "If an attacker can guess or steal a session ID, then they may be able to take over the user's session (called session hijacking). The number of possible session IDs increases with increased session ID length, making it more difficult to guess or steal a session ID.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Session identifiers should be at least 128 bits long to prevent brute-force session guessing. A shorter session identifier leaves the application open to brute-force session guessing attacks.", "phase": ["Implementation"]}, {"description": "A lower bound on the number of valid session identifiers that are available to be guessed is the number of users that are active on a site at any given moment. However, any users that abandon their sessions without logging out will increase this number. (This is one of many good reasons to have a sh...", "phase": ["Implementation"]}], "platforms": {"languages": ["Java"], "technologies": ["Web Based", "Web Server"]}}, "600": {"name": "Uncaught Exception in Servlet ", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The Servlet does not catch all exceptions, which may reveal sensitive debugging information.", "extended_description": "When a Servlet throws an exception, the default error response the Servlet container sends back to the user typically includes debugging information. This information is of great value to an attacker. For example, a stack trace might show the attacker a malformed SQL query string, the type of database being used, and the version of the application container. This information enables the attacker to target known vulnerabilities in these components.", "consequences": [{"scope": ["Confidentiality", "Availability"], "impact": ["Read Application Data", "DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Implement Exception blocks to handle all types of Exceptions.", "phase": ["Implementation"]}], "platforms": {"languages": ["Java"], "technologies": ["Web Server"]}}, "601": {"name": "URL Redirection to Untrusted Site ('Open Redirect')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}, {"scope": ["Access Control", "Confidentiality", "Other"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity", "Other"]}], "mitigations": [{"description": "Use an intermediate disclaimer page that provides the user with a clear warning that they are leaving the current site. Implement a long timeout before the redirect occurs, or force the user to click on the link. Be careful to avoid XSS problems (CWE-79) when generating the disclaimer page.", "phase": ["Architecture and Design"]}, {"description": "Ensure that no externally-supplied requests are honored by requiring that all redirect requests include a unique nonce generated by the application [REF-483]. Be sure that the nonce is not predictable (CWE-330).", "phase": ["Architecture and Design"]}, {"description": "Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide d...", "phase": ["Operation"]}], "detection_methods": [{"method": "Manual Static Analysis", "description": "Since this weakness does not typically appear frequently within a single software package, manual white box techniques may be able to provide sufficient code coverage and reduction of false positives ..."}, {"method": "Automated Dynamic Analysis", "description": "Automated black box tools that supply URLs to every input may be able to spot Location header modifications, but test case coverage is a factor, and custom redirects may not be detected."}, {"method": "Automated Static Analysis", "description": "Automated static analysis tools may not be able to determine whether input influences the beginning of a URL, which is important for reducing false positives."}], "observed_examples": [{"cve": "CVE-2005-4206", "description": "URL parameter loads the URL into a frame and causes it to appear to be part of a valid page."}, {"cve": "CVE-2008-2951", "description": "An open redirect vulnerability in the search script in the software allows remote attackers to redirect users to arbitrary web sites and conduct phish..."}, {"cve": "CVE-2008-2052", "description": "Open redirect vulnerability in the software allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in..."}, {"cve": "CVE-2020-11053", "description": "Chain: Go-based Oauth2 reverse proxy can send the authenticated user to another site at the end of the authentication flow. A redirect URL with HTML-e..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "602": {"name": "Client-Side Enforcement of Server-Side Security", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.", "extended_description": "When the server relies on protection mechanisms placed on the client side, an attacker can modify the client-side behavior to bypass the protection mechanisms, resulting in potentially unexpected interactions between the client and server. The consequences will vary, depending on what the mechanisms are trying to protect.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Access Control", "Availability"], "impact": ["Bypass Protection Mechanism", "DoS: Crash, Exit, or Restart"]}, {"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "If some degree of trust is required between the two entities, then use integrity checking and strong authentication to ensure that the inputs are coming from a trusted source. Design the product so that this trust is managed in a centralized fashion, especially if there are complex or numerous commu...", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Fuzzing", "description": "Use dynamic tools and techniques that\n\t     interact with the software using large test suites with\n\t     many diverse inputs, such as fuzz testing (fuzzing),\n\t     robustness testing, and fault injec..."}, {"method": "Manual Analysis", "description": "Use tools and techniques that require manual (human) analysis, such as penetration testing, threat modeling, and interactive tools that allow the tester to record and modify an active session. These m..."}], "observed_examples": [{"cve": "CVE-2024-50653", "description": "Chain: e-commerce product has a \"front-end restriction\" for coupon use (CWE-602), but the server does not restrict the number of requests for the same..."}, {"cve": "CVE-2022-33139", "description": "SCADA system only uses client-side authentication, allowing adversaries to impersonate other users."}, {"cve": "CVE-2006-6994", "description": "ASP program allows upload of .asp files by bypassing client-side checks."}, {"cve": "CVE-2007-0163", "description": "steganography products embed password information in the carrier file, which can be extracted from a modified client."}, {"cve": "CVE-2007-0164", "description": "steganography products embed password information in the carrier file, which can be extracted from a modified client."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["ICS/OT", "Mobile"]}}, "603": {"name": "Use of Client-Side Authentication", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A client/server product performs authentication within client code but not in server code, allowing server-side authentication to be bypassed via a modified client that omits the authentication check.", "extended_description": "Client-side authentication is extremely weak and may be breached easily. Any attacker may read the source code and reverse-engineer the authentication mechanism to access parts of the application which would otherwise be protected.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Do not rely on client side data. Always perform server side authentication.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2022-33139", "description": "SCADA system only uses client-side authentication, allowing adversaries to impersonate other users."}, {"cve": "CVE-2006-0230", "description": "Client-side check for a password allows access to a server using crafted XML requests from a modified client."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["ICS/OT"]}}, "605": {"name": "Multiple Binds to the Same Port", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "When multiple sockets are allowed to bind to the same port, other services on that port may be stolen or spoofed.", "extended_description": "On most systems, a combination of setting the SO_REUSEADDR socket option, and a call to bind() allows any process to bind to a port to which a previous process has bound with INADDR_ANY. This allows a user to bind to the specific address of a server bound to INADDR_ANY on an unprivileged port, and steal its UDP packets/TCP connection.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Restrict server socket address to known local addresses.", "phase": ["Policy"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "606": {"name": "Unchecked Input for Loop Condition", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly check inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)"]}], "mitigations": [{"description": "Do not use user-controlled data for loop conditions.", "phase": ["Implementation"]}, {"description": "Perform input validation.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "607": {"name": "Public Static Final Field References Mutable Object", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "A public or protected static final field references a mutable object, which allows the object to be changed by malicious code, or accidentally from another package.", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}], "mitigations": [{"description": "Protect mutable objects by making them private. Restrict access to the getter and setter as well.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "608": {"name": "Struts: Non-private Field in ActionForm Class", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "An ActionForm class contains a field that has not been declared private, which can be accessed without using a setter or getter.", "consequences": [{"scope": ["Integrity", "Confidentiality"], "impact": ["Modify Application Data", "Read Application Data"]}], "mitigations": [{"description": "Make all fields private. Use getter to get the value of the field. Setter should be used only by the framework; setting an action form field from other actions is bad practice and should be avoided.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "609": {"name": "Double-Checked Locking", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses double-checked locking to access a resource without the overhead of explicit synchronization, but the locking is insufficient.", "extended_description": "Double-checked locking refers to the situation where a programmer checks to see if a resource has been initialized, grabs a lock, checks again to see if the resource has been initialized, and then performs the initialization if it has not occurred yet. This should not be done, as it is not guaranteed to work in all languages and on all architectures. In summary, other threads may not be operating inside the synchronous block and are not guaranteed to see the operations execute in the same order ...", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Modify Application Data", "Alter Execution Logic"]}], "mitigations": [{"description": "While double-checked locking can be achieved in some languages, it is inherently flawed in Java before 1.5, and cannot be achieved without compromising platform independence. Before Java 1.5, only use of the synchronized keyword is known to work. Beginning in Java 1.5, use of the \"volatile\" keyword ...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Java"]}}, "61": {"name": "UNIX Symbolic Link (Symlink) Following", "abstraction": "Compound", "mapping": "ALLOWED", "structure": "Composite", "description": "The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.", "extended_description": "A product that allows UNIX symbolic links (symlink) as part of paths whether in internal code or through user input can allow an attacker to spoof the symbolic link and traverse the file system to unintended locations or access arbitrary files. The symbolic link can permit an attacker to read/write/corrupt a file that they originally did not have permissions to access.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Symbolic link attacks often occur when a program creates a tmp directory that stores files/links. Access to the directory should be restricted to the program as to prevent attackers from manipulating the files.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-1999-1386", "description": "Some versions of Perl follow symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attac..."}, {"cve": "CVE-2000-1178", "description": "Text editor follows symbolic links when creating a rescue copy during an abnormal exit, which allows local users to overwrite the files of other users..."}, {"cve": "CVE-2004-0217", "description": "Antivirus update allows local users to create or append to arbitrary files via a symlink attack on a logfile."}, {"cve": "CVE-2003-0517", "description": "Symlink attack allows local users to overwrite files."}, {"cve": "CVE-2004-0689", "description": "Possible interesting example"}], "platforms": {"languages": ["Not Language-Specific"]}}, "610": {"name": "Externally Controlled Reference to a Resource in Another Sphere", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data"]}, {"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "observed_examples": [{"cve": "CVE-2022-3032", "description": "An email client does not block loading of remote objects in a nested document."}, {"cve": "CVE-2022-45918", "description": "Chain: a learning management tool debugger uses external input to locate previous session logs (CWE-73) and does not properly validate the given path ..."}, {"cve": "CVE-2018-1000613", "description": "Cryptography API uses unsafe reflection when deserializing a private key"}, {"cve": "CVE-2020-11053", "description": "Chain: Go-based Oauth2 reverse proxy can send the authenticated user to another site at the end of the authentication flow. A redirect URL with HTML-e..."}, {"cve": "CVE-2022-42745", "description": "Recruiter software allows reading arbitrary files using XXE"}], "platforms": {"languages": ["Not Language-Specific"]}}, "611": {"name": "Improper Restriction of XML External Entity Reference", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data", "Read Files or Directories"]}, {"scope": ["Integrity"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)"]}], "mitigations": [{"description": "Many XML parsers and validators can be configured to disable external entity expansion.", "phase": ["Implementation", "System Configuration"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-42745", "description": "Recruiter software allows reading arbitrary files using XXE"}, {"cve": "CVE-2005-1306", "description": "A browser control can allow remote attackers to determine the existence of files via Javascript containing XML script."}, {"cve": "CVE-2012-5656", "description": "XXE during SVG image conversion"}, {"cve": "CVE-2012-2239", "description": "XXE in PHP application allows reading the application's configuration file."}, {"cve": "CVE-2012-3489", "description": "XXE in database server"}], "platforms": {"languages": ["Not Language-Specific", "XML"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "612": {"name": "Improper Authorization of Index Containing Sensitive Information", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product creates a search index of private or sensitive documents, but it does not properly limit index access to actors who are authorized to see the original information.", "extended_description": "Web sites and other document repositories may apply an indexing routine against a group of private documents to facilitate search.  If the index's results are available to parties who do not have access to the documents being indexed, then attackers could obtain portions of the documents by conducting targeted searches and reading the results.  The risk is especially dangerous if search results include surrounding text that was not part of the search query. This issue can appear in search engine...", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "observed_examples": [{"cve": "CVE-2022-41918", "description": "A search application's access control rules are not properly applied to indices for data streams, allowing for the viewing of sensitive information."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based", "Web Server"]}}, "613": {"name": "Insufficient Session Expiration", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "According to WASC, \"Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.\"", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Set sessions/credentials expiration date.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "614": {"name": "Sensitive Cookie in HTTPS Session Without 'Secure' Attribute", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The Secure attribute for sensitive cookies in HTTPS sessions is not set.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Always set the secure attribute when the cookie should be sent via HTTPS only.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2024-47833", "description": "python library for ML and data science does not use the Secure flag for session cookies"}, {"cve": "CVE-2004-0462", "description": "A product does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in plainte..."}, {"cve": "CVE-2008-3663", "description": "A product does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it ..."}, {"cve": "CVE-2008-3662", "description": "A product does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it ..."}, {"cve": "CVE-2008-0128", "description": "A product does not set the secure flag for a cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for..."}], "platforms": {"technologies": ["Web Based"]}}, "615": {"name": "Inclusion of Sensitive Information in Source Code Comments", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "While adding general comments is very useful, some programmers tend to leave important data, such as: filenames related to the web application, old links or links which were not meant to be browsed by users, old code fragments, etc.", "extended_description": "An attacker who finds these comments can map the application's structure and files, expose hidden parts of the site, and study the fragments of code to reverse engineer the application, which may help develop further attacks against the site.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Remove comments which have sensitive information about the design/implementation of the application. Some of the comments may be exposed to the user and affect the security posture of the application.", "phase": ["Distribution"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2007-6197", "description": "Version numbers and internal hostnames leaked in HTML comments."}, {"cve": "CVE-2007-4072", "description": "CMS places full pathname of server in HTML comment."}, {"cve": "CVE-2009-2431", "description": "blog software leaks real username in HTML comment."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "616": {"name": "Incomplete Identification of Uploaded File Variables (PHP)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The PHP application uses an old method for processing uploaded files by referencing the four global variables that are set for each file (e.g. $varname, $varname_size, $varname_name, $varname_type). These variables could be overwritten by attackers, causing the application to process unauthorized files.", "extended_description": "These global variables could be overwritten by POST requests, cookies, or other methods of populating or overwriting these variables. This could be used to read or process arbitrary files by providing values such as \"/etc/passwd\".", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "mitigations": [{"description": "Use PHP 4 or later.", "phase": ["Architecture and Design"]}, {"description": "If you must support older PHP versions, write your own version of is_uploaded_file() and run it against $HTTP_POST_FILES['userfile']))", "phase": ["Architecture and Design"]}, {"description": "For later PHP versions, reference uploaded files using the $HTTP_POST_FILES or $_FILES variables, and use is_uploaded_file() or move_uploaded_file() to ensure that you are dealing with an uploaded file.", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-1460", "description": "Forum does not properly verify whether a file was uploaded or if the associated variables were set by POST, allowing remote attackers to read arbitrar..."}, {"cve": "CVE-2002-1759", "description": "Product doesn't check if the variables for an upload were set by uploading the file, or other methods such as $_POST."}, {"cve": "CVE-2002-1710", "description": "Product does not distinguish uploaded file from other files."}], "platforms": {"languages": ["PHP"]}}, "617": {"name": "Reachable Assertion", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Make sensitive open/close operation non reachable by directly user-controlled data (e.g. open/close resources)", "phase": ["Implementation"]}, {"description": "Perform input validation on user data.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2024-8768", "description": "API server for LLM library can crash when provided an empty prompt, which triggers a reachable  assertion"}, {"cve": "CVE-2023-49286", "description": "Chain: function in web caching proxy does not correctly check a return value (CWE-253) leading to a reachable assertion (CWE-617)"}, {"cve": "CVE-2006-6767", "description": "FTP server allows remote attackers to cause a denial of service (daemon abort) via crafted commands which trigger an assertion failure."}, {"cve": "CVE-2006-6811", "description": "Chat client allows remote attackers to cause a denial of service (crash) via a long message string when connecting to a server, which causes an assert..."}, {"cve": "CVE-2006-5779", "description": "Product allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, which triggers an assertio..."}], "platforms": {"languages": ["Not Language-Specific", "C", "Java", "Rust"], "technologies": ["Not Technology-Specific"]}}, "618": {"name": "Exposed Unsafe ActiveX Method", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "An ActiveX control is intended for use in a web browser, but it exposes dangerous methods that perform actions that are outside of the browser's security model (e.g. the zone or domain).", "extended_description": "ActiveX controls can exercise far greater control over the operating system than typical Java or javascript. Exposed methods can be subject to various vulnerabilities, depending on the implemented behaviors of those methods, and whether input validation is performed on the provided arguments. If there is no integrity checking or origin validation, this method could be invoked by attackers.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "mitigations": [{"description": "If you must expose a method, make sure to perform input validation on all arguments, and protect against all possible vulnerabilities.", "phase": ["Implementation"]}, {"description": "Use code signing, although this does not protect against any weaknesses that are already in the control.", "phase": ["Architecture and Design"]}, {"description": "Where possible, avoid marking the control as safe for scripting.", "phase": ["Architecture and Design", "System Configuration"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2007-1120", "description": "download a file to arbitrary folders."}, {"cve": "CVE-2006-6838", "description": "control downloads and executes a url in a parameter"}, {"cve": "CVE-2007-0321", "description": "resultant buffer overflow"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based"]}}, "619": {"name": "Dangling Database Cursor ('Cursor Injection')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "If a database cursor is not closed properly, then it could become accessible to other users while retaining the same privileges that were originally assigned, leaving the cursor \"dangling.\"", "extended_description": "For example, an improper dangling cursor could arise from unhandled exceptions. The impact of the issue depends on the cursor's role, but SQL injection attacks are commonly possible.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data"]}], "mitigations": [{"description": "Close cursors immediately after access to them is complete. Ensure that you close cursors if exceptions occur.", "phase": ["Implementation"]}], "platforms": {"languages": ["SQL"], "technologies": ["Database Server"]}}, "62": {"name": "UNIX Hard Link", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product, when opening a file or directory, does not sufficiently account for when the name is associated with a hard link to a target that is outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.", "extended_description": "Failure for a system to check for hard links can result in vulnerability to different types of attacks. For example, an attacker can escalate their privileges if a file used by a privileged program is replaced with a hard link to a sensitive file (e.g. /etc/passwd). When the process opens the file, the attacker can assume the privileges of that process.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "observed_examples": [{"cve": "CVE-2001-1494", "description": "Hard link attack, file overwrite; interesting because program checks against soft links"}, {"cve": "CVE-2002-0793", "description": "Hard link and possibly symbolic link following vulnerabilities in embedded operating system allow local users to overwrite arbitrary files."}, {"cve": "CVE-2003-0578", "description": "Server creates hard links and unlinks files as root, which allows local users to gain privileges by deleting and overwriting arbitrary files."}, {"cve": "CVE-1999-0783", "description": "Operating system allows local users to conduct a denial of service by creating a hard link from a device special file to a file on an NFS file system."}, {"cve": "CVE-2004-1603", "description": "Web hosting manager follows hard links, which allows local users to read or modify arbitrary files."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "620": {"name": "Unverified Password Change", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.", "extended_description": "This could be used by an attacker to change passwords for another user, thus gaining the privileges associated with that user.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "When prompting for a password change, force the user to provide the original password in addition to the new password.", "phase": ["Architecture and Design"]}, {"description": "Do not use \"forgotten password\" functionality. But if you must, ensure that you are only providing information to the actual user, e.g. by using an email address or challenge question that the legitimate user already provided in the past; do not allow the current user to change this identity informa...", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2007-0681", "description": "Web app allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unautho..."}, {"cve": "CVE-2000-0944", "description": "Web application password change utility doesn't check the original password."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "621": {"name": "Variable Extraction Error", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input to determine the names of variables into which information is extracted, without verifying that the names of the specified variables are valid. This could cause the program to overwrite unintended variables.", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}], "mitigations": [{"description": "Use allowlists of variable names that can be extracted.", "phase": ["Implementation"]}, {"description": "Consider refactoring your code to avoid extraction routines altogether.", "phase": ["Implementation"]}, {"description": "In PHP, call extract() with options such as EXTR_SKIP and EXTR_PREFIX_ALL; call import_request_variables() with a prefix argument. Note that these capabilities are not present in all PHP versions.", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2006-7135", "description": "extract issue enables file inclusion"}, {"cve": "CVE-2006-7079", "description": "Chain: PHP app uses extract for register_globals compatibility layer (CWE-621), enabling path traversal (CWE-22)"}, {"cve": "CVE-2007-0649", "description": "extract() buried in include files makes post-disclosure analysis confusing; original report had seemed incorrect."}, {"cve": "CVE-2006-6661", "description": "extract() enables static code injection"}, {"cve": "CVE-2006-2828", "description": "import_request_variables() buried in include files makes post-disclosure analysis confusing"}], "platforms": {"languages": ["PHP"]}}, "622": {"name": "Improper Validation of Function Hook Arguments", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product adds hooks to user-accessible API functions, but it does not properly validate the arguments. This could lead to resultant vulnerabilities.", "extended_description": "Such hooks can be used in defensive software that runs with privileges, such as anti-virus or firewall, which hooks kernel calls. When the arguments are not validated, they could be used to bypass the protection scheme or attack the product itself.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Ensure that all arguments are verified, as defined by the API you are protecting.", "phase": ["Architecture and Design"]}, {"description": "Drop privileges before invoking such functions, if possible.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2007-0708", "description": "DoS in firewall using standard Microsoft functions"}, {"cve": "CVE-2006-7160", "description": "DoS in firewall using standard Microsoft functions"}, {"cve": "CVE-2007-1376", "description": "function does not verify that its argument is the proper type, leading to arbitrary memory write"}, {"cve": "CVE-2007-1220", "description": "invalid syscall arguments bypass code execution limits"}, {"cve": "CVE-2006-4541", "description": "DoS in IDS via NULL argument"}], "platforms": {"languages": ["Not Language-Specific"]}}, "623": {"name": "Unsafe ActiveX Control Marked Safe For Scripting", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "An ActiveX control is intended for restricted use, but it has been marked as safe-for-scripting.", "extended_description": "This might allow attackers to use dangerous functionality via a web page that accesses the control, which can lead to different resultant vulnerabilities, depending on the control's behavior.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "During development, do not mark it as safe for scripting.", "phase": ["Architecture and Design"]}, {"description": "After distribution, you can set the kill bit for the control so that it is not accessible from Internet Explorer.", "phase": ["System Configuration"]}], "observed_examples": [{"cve": "CVE-2007-0617", "description": "control allows attackers to add malicious email addresses to bypass spam limits"}, {"cve": "CVE-2007-0219", "description": "web browser uses certain COM objects as ActiveX"}, {"cve": "CVE-2006-6510", "description": "kiosk allows bypass to read files"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based"]}}, "624": {"name": "Executable Regular Expression Error", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a regular expression that either (1) contains an executable component with user-controlled inputs, or (2) allows a user to enable execution by inserting pattern modifiers.", "extended_description": "Case (2) is possible in the PHP preg_replace() function, and possibly in other languages when a user-controlled input is inserted into a string that is later parsed as a regular expression.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "The regular expression feature in some languages allows inputs to be quoted or escaped before insertion, such as \\Q and \\E in Perl.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2006-2059", "description": "Executable regexp in PHP by inserting \"e\" modifier into first argument to preg_replace"}, {"cve": "CVE-2005-3420", "description": "Executable regexp in PHP by inserting \"e\" modifier into first argument to preg_replace"}, {"cve": "CVE-2006-2878", "description": "Complex curly syntax inserted into the replacement argument to PHP preg_replace(), which uses the \"/e\" modifier"}, {"cve": "CVE-2006-2908", "description": "Function allows remote attackers to execute arbitrary PHP code via the username field, which is used in a preg_replace function call with a /e (execut..."}], "platforms": {"languages": ["PHP", "Perl"]}}, "625": {"name": "Permissive Regular Expression", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a regular expression that does not sufficiently restrict the set of allowed values.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "When applicable, ensure that the regular expression marks beginning and ending string patterns, such as \"/^string$/\" for Perl.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2021-22204", "description": "Chain: regex in EXIF processor code does not correctly determine where a string ends (CWE-625), enabling eval injection (CWE-95), as exploited in the ..."}, {"cve": "CVE-2006-1895", "description": "\".*\" regexp leads to static code injection"}, {"cve": "CVE-2002-2175", "description": "insertion of username into regexp results in partial comparison, causing wrong database entry to be updated when one username is a substring of anothe..."}, {"cve": "CVE-2006-4527", "description": "regexp intended to verify that all characters are legal, only checks that at least one is legal, enabling file inclusion."}, {"cve": "CVE-2005-1949", "description": "Regexp for IP address isn't anchored at the end, allowing appending of shell metacharacters."}], "platforms": {"languages": ["Perl", "PHP"]}}, "626": {"name": "Null Byte Interaction Error (Poison Null Byte)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly handle null bytes or NUL characters when passing data between different representations or components.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Remove null bytes from all incoming strings.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2005-4155", "description": "NUL byte bypasses PHP regular expression check"}, {"cve": "CVE-2005-3153", "description": "inserting SQL after a NUL byte bypasses allowlist regexp, enabling SQL injection"}], "platforms": {"languages": ["PHP", "Perl", "ASP.NET"]}}, "627": {"name": "Dynamic Variable Evaluation", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "In a language where the user can influence the name of a variable at runtime, if the variable names are not controlled, an attacker can read or write to arbitrary variables, or access arbitrary functions.", "extended_description": "The resultant vulnerabilities depend on the behavior of the application, both at the crossover point and in any control/data flow that is reachable by the related variables or functions.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Modify Application Data", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Refactor the code to avoid dynamic variable evaluation whenever possible.", "phase": ["Implementation"]}, {"description": "Use only allowlists of acceptable variable or function names.", "phase": ["Implementation"]}, {"description": "For function names, ensure that you are only calling functions that accept the proper number of arguments, to avoid unexpected null arguments.", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2009-0422", "description": "Chain: Dynamic variable evaluation allows resultant remote file inclusion and path traversal."}, {"cve": "CVE-2007-2431", "description": "Chain: dynamic variable evaluation in PHP program used to modify critical, unexpected $_SERVER variable for resultant XSS."}, {"cve": "CVE-2006-4904", "description": "Chain: dynamic variable evaluation in PHP program used to conduct remote file inclusion."}, {"cve": "CVE-2006-4019", "description": "Dynamic variable evaluation in mail program allows reading and modifying attachments and preferences of other users."}], "platforms": {"languages": ["PHP", "Perl"]}}, "628": {"name": "Function Call with Incorrectly Specified Arguments", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product calls a function, procedure, or routine with arguments that are not correctly specified, leading to always-incorrect behavior and resultant weaknesses.", "consequences": [{"scope": ["Other", "Access Control"], "impact": ["Quality Degradation", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Once found, these issues are easy to fix. Use code inspection tools and relevant compiler features to identify potential violations. Pay special attention to code that is not likely to be exercised heavily during QA.", "phase": ["Build and Compilation"]}, {"description": "Make sure your API's are stable before you use them in production code.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Other", "description": "Since these bugs typically introduce incorrect behavior that is obvious to users, they are found quickly, unless they occur in rarely-tested code paths. Managing the correct number of arguments can be..."}], "observed_examples": [{"cve": "CVE-2006-7049", "description": "The method calls the functions with the wrong argument order, which allows remote attackers to bypass intended access restrictions."}], "platforms": {"languages": ["Not Language-Specific"]}}, "636": {"name": "Not Failing Securely ('Failing Open')", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.", "extended_description": "By entering a less secure state, the product inherits the weaknesses associated with that state, making it easier to compromise. At the least, it causes administrators to have a false sense of security. This weakness typically occurs as a result of wanting to \"fail functional\" to minimize administration and support costs, instead of \"failing safe.\"", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Subdivide and allocate resources and components so that a failure in one part does not affect the entire product.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2007-5277", "description": "The failure of connection attempts in a web browser resets DNS pin restrictions. An attacker can then bypass the same origin policy by rebinding a dom..."}, {"cve": "CVE-2006-4407", "description": "Incorrect prioritization leads to the selection of a weaker cipher. Although it is not known whether this issue occurred in implementation or design, ..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "ICS/OT"]}}, "637": {"name": "Unnecessary Complexity in Protection Mechanism (Not Using 'Economy of Mechanism')", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product uses a more complex mechanism than necessary, which could lead to resultant weaknesses when the mechanism is not correctly understood, modeled, configured, implemented, or used.", "extended_description": "Security mechanisms should be as simple as possible. Complex security mechanisms may engender partial implementations and compatibility problems, with resulting mismatches in assumptions and implemented security. A corollary of this principle is that data specifications should be as simple as possible, because complex data specifications result in complex validation code. Complex tasks and systems may also need to be guarded by complex security checks, so simple systems should be preferred.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "mitigations": [{"description": "Avoid complex security mechanisms when simpler ones would meet requirements. Avoid complex data models, and unnecessarily complex operations. Adopt architectures that provide guarantees, simplify understanding through elegance and abstraction, and that can be implemented similarly. Modularize, isola...", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2007-6067", "description": "Support for complex regular expressions leads to a resultant algorithmic complexity weakness (CWE-407)."}, {"cve": "CVE-2007-1552", "description": "Either a filename extension and a Content-Type header could be used to infer the file type, but the developer only checks the Content-Type, enabling u..."}, {"cve": "CVE-2007-6479", "description": "In Apache environments, a \"filename.php.gif\" can be redirected to the PHP interpreter instead of being sent as an image/gif directly to the user. Not ..."}, {"cve": "CVE-2005-2148", "description": "The developer cleanses the $_REQUEST superglobal array, but PHP also populates $_GET, allowing attackers to bypass the protection mechanism and conduc..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "638": {"name": "Not Using Complete Mediation", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not perform access checks on a resource every time the resource is accessed by an entity, which can create resultant weaknesses if that entity's rights or privileges change over time.", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability", "Access Control", "Other"], "impact": ["Gain Privileges or Assume Identity", "Execute Unauthorized Code or Commands", "Bypass Protection Mechanism", "Read Application Data", "Other"]}], "mitigations": [{"description": "Invalidate cached privileges, file handles or descriptors, or other access credentials whenever identities, processes, policies, roles, capabilities or permissions change. Perform complete authentication checks before accepting, caching and reusing data, dynamic content and code (scripts). Avoid cac...", "phase": ["Architecture and Design"]}, {"description": "Identify all possible code paths that might access sensitive resources. If possible, create and use a single interface that performs the access checks, and develop code standards that require use of this interface.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2007-0408", "description": "Server does not properly validate client certificates when reusing cached connections."}], "platforms": {"languages": ["Not Language-Specific"]}}, "639": {"name": "Authorization Bypass Through User-Controlled Key", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "For each and every data access, ensure that the user has sufficient privilege to access the record that is being requested.", "phase": ["Architecture and Design"]}, {"description": "Make sure that the key that is used in the lookup of a specific user's record is not controllable externally by the user or that any tampering can be detected.", "phase": ["Architecture and Design", "Implementation"]}, {"description": "Use encryption in order to make it more difficult to guess other legitimate values of the key or associate a digital signature with the key so that the server can verify that there has been no tampering.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2021-36539", "description": "An educational application does not appropriately restrict file IDs to a particular user. The attacker can brute-force guess IDs, indicating IDOR."}], "platforms": {"languages": ["Not Language-Specific"]}}, "64": {"name": "Windows Shortcut Following (.LNK)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product, when opening a file or directory, does not sufficiently handle when the file is a Windows shortcut (.LNK) whose target is outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "observed_examples": [{"cve": "CVE-2019-19793", "description": "network access control service executes program with high privileges and allows symlink to invoke another executable or perform DLL injection."}, {"cve": "CVE-2000-0342", "description": "Mail client allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refer..."}, {"cve": "CVE-2001-1042", "description": "FTP server allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file."}, {"cve": "CVE-2001-1043", "description": "FTP server allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file."}, {"cve": "CVE-2005-0587", "description": "Browser allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrite..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "640": {"name": "Weak Password Recovery Mechanism for Forgotten Password", "abstraction": "Base", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Availability"], "impact": ["DoS: Resource Consumption (Other)"]}, {"scope": ["Integrity", "Other"], "impact": ["Other"]}], "mitigations": [{"description": "Make sure that all input supplied by the user to the password recovery mechanism is thoroughly filtered and validated.", "phase": ["Architecture and Design"]}, {"description": "Do not use standard weak security questions and use several security questions.", "phase": ["Architecture and Design"]}, {"description": "Make sure that there is throttling on the number of incorrect answers to a security question. Disable the password recovery functionality after a certain (small) number of incorrect guesses.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "641": {"name": "Improper Restriction of Names for Files and Other Resources", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product constructs the name of a file or other resource using input from an upstream component, but it does not restrict or incorrectly restricts the resulting name.", "extended_description": "This may produce resultant weaknesses. For instance, if the names of these resources contain scripting characters, it is possible that a script may get executed in the client's browser if the application ever displays the name of the resource on a dynamically generated web page. Alternately, if the resources are consumed by some application parser, a specially crafted name can exploit some vulnerability internal to the parser, potentially resulting in execution of arbitrary code on the server ma...", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Confidentiality", "Availability"], "impact": ["Read Application Data", "DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Do not allow users to control names of resources used on the server side.", "phase": ["Architecture and Design"]}, {"description": "Perform allowlist input validation at entry points and also before consuming the resources. Reject bad file names rather than trying to cleanse them.", "phase": ["Architecture and Design"]}, {"description": "Make sure that technologies consuming the resources are not vulnerable (e.g. buffer overflow, format string, etc.) in a way that would allow code execution if the name of the resource is malformed.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "642": {"name": "External Control of Critical State Data", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product stores security-critical state information about its users, or the product itself, in a location that is accessible to unauthorized actors.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Understand all the potential locations that are accessible to attackers. For example, some programmers assume that cookies and hidden form fields cannot be modified by an attacker, or they may not consider that environment variables can be modified before a privileged program is invoked.", "phase": ["Architecture and Design"]}, {"description": "Store state information on the server side only. Ensure that the system definitively and unambiguously keeps track of its own state and user state and has rules defined for legitimate state transitions. Do not allow any application user to affect state directly in any way other than through legitima...", "phase": ["Architecture and Design"]}, {"description": "For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-s...", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Fuzzing", "description": "Use dynamic tools and techniques that\n\t     interact with the product using large test suites with\n\t     many diverse inputs, such as fuzz testing (fuzzing),\n\t     robustness testing, and fault inject..."}], "observed_examples": [{"cve": "CVE-2005-2428", "description": "Mail client stores password hashes for unrelated accounts in a hidden form field."}, {"cve": "CVE-2008-0306", "description": "Privileged program trusts user-specified environment variable to modify critical configuration settings."}, {"cve": "CVE-1999-0073", "description": "Telnet daemon allows remote clients to specify critical environment variables for the server, leading to code execution."}, {"cve": "CVE-2007-4432", "description": "Untrusted search path vulnerability through modified LD_LIBRARY_PATH environment variable."}, {"cve": "CVE-2006-7191", "description": "Untrusted search path vulnerability through modified LD_LIBRARY_PATH environment variable."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Server"]}}, "643": {"name": "Improper Neutralization of Data within XPath Expressions ('XPath Injection')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input to dynamically construct an XPath expression used to retrieve data from an XML database, but it does not neutralize or incorrectly neutralizes that input. This allows an attacker to control the structure of the query.", "extended_description": "The net effect is that the attacker will have control over the information selected from the XML database and may use that ability to control application flow, modify logic, retrieve unauthorized data, or bypass important checks (e.g. authentication).", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Use parameterized XPath queries (e.g. using XQuery). This will help ensure separation between data plane and control plane.", "phase": ["Implementation"]}, {"description": "Properly validate user input. Reject data where appropriate, filter where appropriate and escape where appropriate. Make sure input that will be used in XPath queries is safe in that context.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "644": {"name": "Improper Neutralization of HTTP Headers for Scripting Syntax", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers, such as Flash.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Perform output validation in order to filter/escape/encode unsafe data that is being passed from the server in an HTTP response header.", "phase": ["Architecture and Design"]}, {"description": "Disable script execution functionality in the clients' browser.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2006-3918", "description": "Web server does not remove the Expect header from an HTTP request when it is reflected back in an error message, allowing a Flash SWF file to perform ..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "645": {"name": "Overly Restrictive Account Lockout Mechanism", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains an account lockout protection mechanism, but the mechanism is too restrictive and can be triggered too easily, which allows attackers to deny service to legitimate users by causing their accounts to be locked out.", "extended_description": "Account lockout is a security feature often present in applications as a countermeasure to the brute force attack on the password based authentication mechanism of the system. After a certain number of failed login attempts, the users' account may be disabled for a certain period of time or until it is unlocked by an administrator. Other security events may also possibly trigger account lockout. However, an attacker may use this very security feature to deny service to legitimate system users. I...", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (Other)"]}], "mitigations": [{"description": "Implement more intelligent password throttling mechanisms such as those which take IP address into account, in addition to the login name.", "phase": ["Architecture and Design"]}, {"description": "Implement a lockout timeout that grows as the number of incorrect login attempts goes up, eventually resulting in a complete lockout.", "phase": ["Architecture and Design"]}, {"description": "Consider alternatives to account lockout that would still be effective against password brute force attacks, such as presenting the user machine with a puzzle to solve (makes it do some computation).", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "646": {"name": "Reliance on File Name or Extension of Externally-Supplied File", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product allows a file to be uploaded, but it relies on the file name or extension of the file to determine the appropriate behaviors. This could be used by attackers to cause the file to be misclassified and processed in a dangerous fashion.", "extended_description": "An application might use the file name or extension of a user-supplied file to determine the proper course of action, such as selecting the correct process to which control should be passed, deciding what data should be made available, or what resources should be allocated. If the attacker can cause the code to misclassify the supplied file, then the wrong action could occur. For example, an attacker could supply a file that ends in a \".php.gif\" extension that appears to be a GIF image, but woul...", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Make decisions on the server side based on file content and not on file name or extension.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Server"]}}, "647": {"name": "Use of Non-Canonical URL Paths for Authorization Decisions", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product defines policy namespaces and makes authorization decisions based on the assumption that a URL is canonical. This can allow a non-canonical URL to bypass the authorization.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Confidentiality"], "impact": ["Read Files or Directories"]}], "mitigations": [{"description": "Make access control policy based on path information in canonical form. Use very restrictive regular expressions to validate that the path is in the expected form.", "phase": ["Architecture and Design"]}, {"description": "Reject all alternate path encodings that are not in the expected canonical form.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Server"]}}, "648": {"name": "Incorrect Use of Privileged APIs", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Before calling privileged APIs, always ensure that the assumptions made by the privileged code hold true prior to making the call.", "phase": ["Implementation"]}, {"description": "Know architecture and implementation weaknesses of the privileged APIs and make sure to account for these weaknesses before calling the privileged APIs to ensure that they can be called safely.", "phase": ["Architecture and Design"]}, {"description": "If privileged APIs make certain assumptions about data, context or state validity that are passed by the caller, the calling code must ensure that these assumptions have been validated prior to making the call.", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2003-0645", "description": "A Unix utility that displays online help files, if installed setuid, could allow a local attacker to gain privileges when a particular file-opening fu..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "649": {"name": "Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses obfuscation or encryption of inputs that should not be mutable by an external actor, but the product does not use integrity checks to detect if those inputs have been modified.", "extended_description": "When an application relies on obfuscation or incorrectly applied / weak encryption to protect client-controllable tokens or parameters, that may have an effect on the user state, system state, or some decision made on the server. Without protecting the tokens/parameters for integrity, the application is vulnerable to an attack where an adversary traverses the space of possible values of the said token/parameter in order to attempt to gain an advantage. The goal of the attacker is to find another...", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Protect important client controllable tokens/parameters for integrity using PKI methods (i.e. digital signatures) or other means, and checks for integrity on the server side.", "phase": ["Architecture and Design"]}, {"description": "Repeated requests from a particular user that include invalid values of tokens/parameters (those that should not be changed manually by users) should result in the user account lockout.", "phase": ["Architecture and Design"]}, {"description": "Client side tokens/parameters should not be such that it would be easy/predictable to guess another valid state.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2005-0039", "description": "An IPSec configuration does not perform integrity checking of the IPSec packet as the result of either not configuring ESP properly to support the int..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "65": {"name": "Windows Hard Link", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product, when opening a file or directory, does not sufficiently handle when the name is associated with a hard link to a target that is outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.", "extended_description": "Failure for a system to check for hard links can result in vulnerability to different types of attacks. For example, an attacker can escalate their privileges if a file used by a privileged program is replaced with a hard link to a sensitive file (e.g. AUTOEXEC.BAT). When the process opens the file, the attacker can assume the privileges of that process, or prevent the program from accurately processing data.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "observed_examples": [{"cve": "CVE-2002-0725", "description": "File system allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit..."}, {"cve": "CVE-2003-0844", "description": "Web server plugin allows local users to overwrite arbitrary files via a symlink attack on predictable temporary filenames."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "650": {"name": "Trusting HTTP Permission Methods on the Server Side", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The server contains a protection mechanism that assumes that any URI that is accessed using HTTP GET will not cause a state change to the associated resource. This might allow attackers to bypass intended access restrictions and conduct resource modification and deletion attacks, since some applications allow GET to modify state.", "extended_description": "The HTTP GET method and some other methods are designed to retrieve resources and not to alter the state of the application or resources on the server side. Furthermore, the HTTP specification requires that GET requests (and other requests) should not have side effects. Believing that it will be enough to prevent unintended resource alterations, an application may disallow the HTTP requests to perform DELETE, PUT and POST operations on the resource representation. However, there is nothing in th...", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Integrity"], "impact": ["Modify Application Data"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Configure ACLs on the server side to ensure that proper level of access control is defined for each accessible resource representation.", "phase": ["System Configuration"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "651": {"name": "Exposure of WSDL File Containing Sensitive Information", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The Web services architecture may require exposing a Web Service Definition Language (WSDL) file that contains information on the publicly accessible services and how callers of these services should interact with them (e.g. what parameters they expect and what types they return).", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Limit access to the WSDL file as much as possible. If services are provided only to a limited number of entities, it may be better to provide WSDL privately to each of these entities than to publish WSDL publicly.", "phase": ["Architecture and Design"]}, {"description": "Make sure that WSDL does not describe methods that should not be publicly accessible. Make sure to protect service methods that should not be publicly accessible with access controls.", "phase": ["Architecture and Design"]}, {"description": "Do not use method names in WSDL that might help an adversary guess names of private methods/resources used by the service.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Server"]}}, "652": {"name": "Improper Neutralization of Data within XQuery Expressions ('XQuery Injection')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses external input to dynamically construct an XQuery expression used to retrieve data from an XML database, but it does not neutralize or incorrectly neutralizes that input. This allows an attacker to control the structure of the query.", "extended_description": "The net effect is that the attacker will have control over the information selected from the XML database and may use that ability to control application flow, modify logic, retrieve unauthorized data, or bypass important checks (e.g. authentication).", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Use parameterized queries. This will help ensure separation between data plane and control plane.", "phase": ["Implementation"]}, {"description": "Properly validate user input. Reject data where appropriate, filter where appropriate and escape where appropriate. Make sure input that will be used in XQL queries is safe in that context.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "653": {"name": "Improper Isolation or Compartmentalization", "abstraction": "Class", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.", "extended_description": "When a weakness occurs in functionality that is accessible by lower-privileged users, then without strong boundaries, an attack might extend the scope of the damage to higher-privileged users.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity", "Bypass Protection Mechanism"]}], "mitigations": [{"description": "Break up privileges between different modules, objects, or entities. Minimize the interfaces between modules and require strong access control between them.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Manual Static Analysis - Source Code"}, {"method": "Architecture or Design Review"}], "observed_examples": [{"cve": "CVE-2021-33096", "description": "Improper isolation of shared resource in a network-on-chip leads to denial of service"}, {"cve": "CVE-2019-6260", "description": "Baseboard Management Controller (BMC) device implements Advanced High-performance Bus (AHB) bridges that do not require authentication for arbitrary r..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "654": {"name": "Reliance on a Single Factor in a Security Decision", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A protection mechanism relies exclusively, or to a large extent, on the evaluation of a single condition or the integrity of a single object or entity in order to make a decision about granting access to restricted resources or functionality.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Non-Repudiation"], "impact": ["Hide Activities"]}], "mitigations": [{"description": "Use multiple simultaneous checks before granting access to critical operations or granting critical privileges. A weaker but helpful mitigation is to use several successive checks (multiple layers of security).", "phase": ["Architecture and Design"]}, {"description": "Use redundant access rules on different choke points (e.g., firewalls).", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2022-35248", "description": "Chat application skips validation when Central Authentication Service\n\t\t\t (CAS) is enabled, effectively removing the second factor from\n\t\t\t two-factor..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "655": {"name": "Insufficient Psychological Acceptability", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product has a protection mechanism that is too difficult or inconvenient to use, encouraging non-malicious users to disable or bypass the mechanism, whether by accident or on purpose.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Where possible, perform human factors and usability studies to identify where your product's security mechanisms are difficult to use, and why.", "phase": ["Testing"]}, {"description": "Make the security mechanism as seamless as possible, while also providing the user with sufficient details when a security decision produces unexpected results.", "phase": ["Architecture and Design"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "656": {"name": "Reliance on Security Through Obscurity", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product uses a protection mechanism whose strength depends heavily on its obscurity, such that knowledge of its algorithms or key data is sufficient to defeat the mechanism.", "extended_description": "This reliance on \"security through obscurity\" can produce resultant weaknesses if an attacker is able to reverse engineer the inner workings of the mechanism. Note that obscurity can be one small part of defense in depth, since it can create more work for an attacker; however, it is a significant risk if used as the primary means of protection.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Other"], "impact": ["Other"]}], "mitigations": [{"description": "Always consider whether knowledge of your code or design is sufficient to break it. Reverse engineering is a highly successful discipline, and financially feasible for motivated adversaries. Black-box techniques are established for binary analysis of executables that use obfuscation, runtime analysi...", "phase": ["Architecture and Design"]}, {"description": "When available, use publicly-vetted algorithms and procedures, as these are more likely to undergo more extensive security analysis and testing. This is especially the case with encryption and authentication.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2006-6588", "description": "Reliance on hidden form fields in a web application. Many web application vulnerabilities exist because the developer did not consider that \"hidden\" f..."}, {"cve": "CVE-2006-7142", "description": "Hard-coded cryptographic key stored in executable program."}, {"cve": "CVE-2005-4002", "description": "Hard-coded cryptographic key stored in executable program."}, {"cve": "CVE-2006-4068", "description": "Hard-coded hashed values for username and password contained in client-side script, allowing brute-force offline attacks."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "657": {"name": "Violation of Secure Design Principles", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product violates well-established principles for secure design.", "extended_description": "This can introduce resultant weaknesses or make it easier for developers to introduce related weaknesses during implementation. Because code is centered around design, it can be resource-intensive to fix design problems.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "observed_examples": [{"cve": "CVE-2019-6260", "description": "Baseboard Management Controller (BMC) device implements Advanced High-performance Bus (AHB) bridges that do not require authentication for arbitrary r..."}, {"cve": "CVE-2007-5277", "description": "The failure of connection attempts in a web browser resets DNS pin restrictions. An attacker can then bypass the same origin policy by rebinding a dom..."}, {"cve": "CVE-2006-7142", "description": "Hard-coded cryptographic key stored in executable program."}, {"cve": "CVE-2007-0408", "description": "Server does not properly validate client certificates when reusing cached connections."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "66": {"name": "Improper Handling of File Names that Identify Virtual Resources", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not handle or incorrectly handles a file name that identifies a \"virtual\" resource that is not directly specified within the directory that is associated with the file name, causing the product to perform file-based operations on a resource that is not a file.", "extended_description": "Virtual file names are represented like normal file names, but they are effectively aliases for other resources that do not behave like normal files. Depending on their functionality, they could be alternate entities. They are not necessarily listed in directories.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "detection_methods": [{"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Manual Static Analysis - Binary or Bytecode"}, {"method": "Dynamic Analysis with Automated Results Interpretation"}], "observed_examples": [{"cve": "CVE-1999-0278", "description": "In IIS, remote attackers can obtain source code for ASP files by appending \"::$DATA\" to the URL."}, {"cve": "CVE-2004-1084", "description": "Server allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data stream..."}, {"cve": "CVE-2002-0106", "description": "Server allows remote attackers to cause a denial of service via a series of requests to .JSP files that contain an MS-DOS device name."}], "platforms": {"languages": ["Not Language-Specific"]}}, "662": {"name": "Improper Synchronization", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product utilizes multiple threads, processes, components, or systems to allow temporary access to a shared resource that can only be exclusive to one process at a time, but it does not properly synchronize these actions, which might cause simultaneous accesses of this resource by multiple threads or processes.", "consequences": [{"scope": ["Integrity", "Confidentiality", "Other"], "impact": ["Modify Application Data", "Read Application Data", "Alter Execution Logic"]}], "mitigations": [{"description": "Use industry standard APIs to synchronize your code.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2021-1782", "description": "Chain: improper locking (CWE-667) leads to race condition (CWE-362), as exploited in the wild per CISA KEV."}, {"cve": "CVE-2009-0935", "description": "Attacker provides invalid address to a memory-reading function, causing a mutex to be unlocked twice"}], "platforms": {"languages": ["Not Language-Specific"]}}, "663": {"name": "Use of a Non-reentrant Function in a Concurrent Context", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product calls a non-reentrant function in a concurrent context in which a competing code sequence (e.g. thread or signal handler) may have an opportunity to call the same function or otherwise influence its state.", "consequences": [{"scope": ["Integrity", "Confidentiality", "Other"], "impact": ["Modify Memory", "Read Memory", "Modify Application Data", "Read Application Data", "Alter Execution Logic"]}], "mitigations": [{"description": "Use reentrant functions if available.", "phase": ["Implementation"]}, {"description": "Add synchronization to your non-reentrant function.", "phase": ["Implementation"]}, {"description": "In Java, use the ReentrantLock Class.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2001-1349", "description": "unsafe calls to library functions from signal handler"}, {"cve": "CVE-2004-2259", "description": "SIGCHLD signal to FTP server can cause crash under heavy load while executing non-reentrant functions like malloc/free."}], "platforms": {"languages": ["Not Language-Specific", "C"]}}, "664": {"name": "Improper Control of a Resource Through its Lifetime", "abstraction": "Pillar", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Use Static analysis tools to check for unreleased resources."}], "observed_examples": [{"cve": "CVE-2018-1000613", "description": "Cryptography API uses unsafe reflection when deserializing a private key"}, {"cve": "CVE-2019-19911", "description": "Chain: Python library does not limit the resources used to process images that specify a very large number of bands (CWE-1284), leading to excessive m..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "665": {"name": "Improper Initialization", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.", "extended_description": "This can have security implications when the associated resource is expected to have certain properties or values, such as a variable that determines whether a user has been authenticated or not.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory", "Read Application Data"]}, {"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Identify all variables and data stores that receive information from external sources, and apply input validation to make sure that they are only initialized to expected values.", "phase": ["Architecture and Design"]}, {"description": "Explicitly initialize all your variables and other data stores, either during declaration or just before the first usage.", "phase": ["Implementation"]}, {"description": "Pay close attention to complex conditionals that affect initialization, since some conditions might not perform the initialization.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Dynamic Analysis"}, {"method": "Manual Dynamic Analysis", "description": "Identify error conditions that are not likely to occur during normal usage and trigger them. For example, run the program under low memory conditions, run with insufficient privileges or permissions, ..."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2001-1471", "description": "chain: an invalid value prevents a library file from being included, skipping initialization of key variables, leading to resultant eval injection."}, {"cve": "CVE-2008-3637", "description": "Improper error checking in protection mechanism produces an uninitialized variable, allowing security bypass and code execution."}, {"cve": "CVE-2008-4197", "description": "Use of uninitialized memory may allow code execution."}, {"cve": "CVE-2008-2934", "description": "Free of an uninitialized pointer leads to crash and possible code execution."}, {"cve": "CVE-2007-3749", "description": "OS kernel does not reset a port when starting a setuid program, allowing local users to access the port and gain privileges."}], "platforms": {"languages": ["Not Language-Specific"]}}, "666": {"name": "Operation on Resource in Wrong Phase of Lifetime", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product performs an operation on a resource at the wrong phase of the resource's lifecycle, which can lead to unexpected behaviors.", "extended_description": "A resource's lifecycle includes several phases: initialization, use, and release. For each phase, it is important to follow the specifications outlined for how to operate on the resource and to ensure that the resource is in the expected phase. Otherwise, if a resource is in one phase but the operation is not valid for that phase (i.e., an incorrect phase of the resource's lifetime), then this can produce resultant weaknesses. For example, using a resource before it has been fully initialized co...", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "mitigations": [{"description": "Follow the resource's lifecycle from creation to release.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2006-5051", "description": "Chain: Signal handler contains too much functionality (CWE-828), introducing a race condition (CWE-362) that leads to a double free (CWE-415)."}], "platforms": {"languages": ["Not Language-Specific"]}}, "667": {"name": "Improper Locking", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not properly acquire or release a lock on a resource, leading to unexpected resource state changes and behaviors.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)"]}], "mitigations": [{"description": "Use industry standard APIs to implement locking mechanism.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2021-1782", "description": "Chain: improper locking (CWE-667) leads to race condition (CWE-362), as exploited in the wild per CISA KEV."}, {"cve": "CVE-2009-0935", "description": "Attacker provides invalid address to a memory-reading function, causing a mutex to be unlocked twice"}, {"cve": "CVE-2010-4210", "description": "function in OS kernel unlocks a mutex that was not previously locked, causing a panic or overwrite of arbitrary memory."}, {"cve": "CVE-2008-4302", "description": "Chain: OS kernel does not properly handle a failure of a function call (CWE-755), leading to an unlock of a resource that was not locked (CWE-832), wi..."}, {"cve": "CVE-2009-1243", "description": "OS kernel performs an unlock in some incorrect circumstances, leading to panic."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "668": {"name": "Exposure of Resource to Wrong Sphere", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Integrity"], "impact": ["Modify Application Data"]}, {"scope": ["Other"], "impact": ["Varies by Context"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "669": {"name": "Incorrect Resource Transfer Between Spheres", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data", "Unexpected State"]}], "observed_examples": [{"cve": "CVE-2021-22909", "description": "Chain: router's firmware update procedure uses curl with \"-k\" (insecure) option that disables certificate validation (CWE-295), allowing adversary-in-..."}, {"cve": "CVE-2023-5227", "description": "PHP-based FAQ management app does not check the MIME type for uploaded images"}, {"cve": "CVE-2005-0406", "description": "Some image editors modify a JPEG image, but the original EXIF thumbnail image is left intact within the JPEG. (Also an interaction error)."}], "platforms": {"languages": ["Not Language-Specific"]}}, "67": {"name": "Improper Handling of Windows Device Names", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product constructs pathnames from user input, but it does not handle or incorrectly handles a pathname containing a Windows device name such as AUX or CON. This typically leads to denial of service or an information exposure when the application attempts to process the pathname as a regular file.", "extended_description": "Not properly handling virtual filenames (e.g. AUX, CON, PRN, COM1, LPT1) can result in different types of vulnerabilities. In some cases an attacker can request a device via injection of a virtual filename in a URL, which may cause an error that leads to a denial of service or an error page that reveals sensitive information. A product that allows device names to bypass filtering runs the risk of an attacker injecting malicious code in a file with the name of a device.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Availability", "Confidentiality", "Other"], "impact": ["DoS: Crash, Exit, or Restart", "Read Application Data", "Other"]}], "mitigations": [{"description": "Be familiar with the device names in the operating system where your system is deployed. Check input for these device names.", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-0106", "description": "Server allows remote attackers to cause a denial of service via a series of requests to .JSP files that contain an MS-DOS device name."}, {"cve": "CVE-2002-0200", "description": "Server allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name."}, {"cve": "CVE-2002-1052", "description": "Product allows remote attackers to use MS-DOS device names in HTTP requests to cause a denial of service or obtain the physical path of the server."}, {"cve": "CVE-2001-0493", "description": "Server allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name."}, {"cve": "CVE-2001-0558", "description": "Server allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name."}], "platforms": {"languages": ["Not Language-Specific"]}}, "670": {"name": "Always-Incorrect Control Flow Implementation", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.", "extended_description": "This weakness captures cases in which a particular code segment is always incorrect with respect to the algorithm that it is implementing. For example, if a C programmer intends to include multiple statements in a single block but does not include the enclosing braces (CWE-483), then the logic is always incorrect. This issue is in contrast to most weaknesses in which the code usually behaves correctly, except when it is externally manipulated in malicious ways.", "consequences": [{"scope": ["Other"], "impact": ["Other", "Alter Execution Logic"]}], "observed_examples": [{"cve": "CVE-2021-3011", "description": "virtual interrupt controller in a virtualization product allows crash of host by writing a certain invalid value to a register, which triggers a fatal..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "671": {"name": "Lack of Administrator Control over Security", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product uses security features in a way that prevents the product's administrator from tailoring security settings to reflect the environment in which the product is being used. This introduces resultant weaknesses or prevents it from operating at a level of security that is desired by the administrator.", "extended_description": "If the product's administrator does not have the ability to manage security-related decisions at all times, then protecting the product from outside threats - including the product's developer - can become impossible. For example, a hard-coded account name and password cannot be changed by the administrator, thus exposing that product to attacks that the administrator can not prevent.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "observed_examples": [{"cve": "CVE-2022-29953", "description": "Condition Monitor firmware has a maintenance interface with hard-coded credentials"}, {"cve": "CVE-2000-0127", "description": "GUI configuration tool does not enable a security option when a checkbox is selected, although that option is honored when manually set in the configu..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "672": {"name": "Operation on a Resource after Expiration or Release", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.", "consequences": [{"scope": ["Integrity", "Confidentiality"], "impact": ["Modify Application Data", "Read Application Data"]}, {"scope": ["Other", "Availability"], "impact": ["Other", "DoS: Crash, Exit, or Restart"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2009-3547", "description": "Chain: race condition (CWE-362) might allow resource to be released before operating on it, leading to NULL dereference (CWE-476)"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Mobile"]}}, "673": {"name": "External Influence of Sphere Definition", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not prevent the definition of control spheres from external actors.", "extended_description": "Typically, a product defines its control sphere within the code itself, or through configuration by the product's administrator. In some cases, an external party can change the definition of the control sphere. This is typically a resultant weakness.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "observed_examples": [{"cve": "CVE-2008-2613", "description": "setuid program allows compromise using path that finds and loads a malicious library."}], "platforms": {"languages": ["Not Language-Specific"]}}, "674": {"name": "Uncontrolled Recursion", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not properly control the amount of recursion that takes place,  consuming excessive resources, such as allocated memory or the program stack.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Ensure an end condition will be reached under all logic conditions.  The end condition may include testing against the depth of recursion and exiting with an error if the recursion goes too deep. The complexity of the end condition contributes to the effectiveness of this action.", "phase": ["Implementation"]}, {"description": "Increase the stack size.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2007-1285", "description": "Deeply nested arrays trigger stack exhaustion."}, {"cve": "CVE-2007-3409", "description": "Self-referencing pointers create infinite loop and resultant stack exhaustion."}, {"cve": "CVE-2016-10707", "description": "Javascript application accidentally changes input in a way that prevents a recursive call from detecting an exit condition."}, {"cve": "CVE-2016-3627", "description": "An attempt to recover a corrupted XML file infinite recursion protection counter was not always incremented missing the exit condition."}, {"cve": "CVE-2019-15118", "description": "USB-audio driver's descriptor code parsing allows unlimited recursion leading to stack exhaustion."}], "platforms": {"languages": ["Not Language-Specific"]}}, "675": {"name": "Multiple Operations on Resource in Single-Operation Context", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product performs the same operation on a resource two or more times, when the operation should only be applied once.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "observed_examples": [{"cve": "CVE-2009-0935", "description": "Attacker provides invalid address to a memory-reading function, causing a mutex to be unlocked twice"}, {"cve": "CVE-2019-13351", "description": "file descriptor double close can cause the wrong file to be associated with a file descriptor."}, {"cve": "CVE-2004-1939", "description": "XSS protection mechanism attempts to remove \"/\" that could be used to close tags, but it can be bypassed using double encoded slashes (%252F)"}], "platforms": {"languages": ["Not Language-Specific"]}}, "676": {"name": "Use of Potentially Dangerous Function", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product invokes a potentially dangerous function that could introduce a vulnerability if it is used incorrectly, but the function can also be used safely.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context", "Quality Degradation", "Unexpected State"]}], "mitigations": [{"description": "Identify a list of prohibited API functions and prohibit developers from using these functions, providing safer alternatives. In some cases, automatic code analysis tools or the compiler can be instructed to spot use of prohibited functions, such as the \"banned.h\" include file from Microsoft's SDL. ...", "phase": ["Build and Compilation", "Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Manual Static Analysis - Binary or Bytecode"}, {"method": "Dynamic Analysis with Manual Results Interpretation"}], "observed_examples": [{"cve": "CVE-2007-1470", "description": "Library has multiple buffer overflows using sprintf() and strcpy()"}, {"cve": "CVE-2009-3849", "description": "Buffer overflow using strcat()"}, {"cve": "CVE-2006-2114", "description": "Buffer overflow using strcpy()"}, {"cve": "CVE-2006-0963", "description": "Buffer overflow using strcpy()"}, {"cve": "CVE-2011-0712", "description": "Vulnerable use of strcpy() changed to use safer strlcpy()"}], "platforms": {"languages": ["C", "C++"]}}, "680": {"name": "Integer Overflow to Buffer Overflow", "abstraction": "Compound", "mapping": "DISCOURAGED", "structure": "Chain", "description": "The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.", "consequences": [{"scope": ["Integrity", "Availability", "Confidentiality"], "impact": ["Modify Memory", "DoS: Crash, Exit, or Restart", "Execute Unauthorized Code or Commands"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2021-43537", "description": "Chain: in a web browser, an unsigned 64-bit integer is forcibly cast to a 32-bit integer (CWE-681) and potentially leading to an integer overflow (CWE..."}, {"cve": "CVE-2017-1000121", "description": "chain: unchecked message size metadata allows integer overflow (CWE-190) leading to buffer overflow (CWE-119)."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "681": {"name": "Incorrect Conversion between Numeric Types", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Other", "Integrity"], "impact": ["Unexpected State", "Quality Degradation"]}], "mitigations": [{"description": "Avoid making conversion between numeric types. Always check for the allowed ranges.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-2639", "description": "Chain: integer coercion error (CWE-192) prevents a return value from indicating an error, leading to out-of-bounds write (CWE-787)"}, {"cve": "CVE-2021-43537", "description": "Chain: in a web browser, an unsigned 64-bit integer is forcibly cast to a 32-bit integer (CWE-681) and potentially leading to an integer overflow (CWE..."}, {"cve": "CVE-2007-4268", "description": "Chain: integer signedness error (CWE-195) passes signed comparison, leading to heap overflow (CWE-122)"}, {"cve": "CVE-2007-4988", "description": "Chain: signed short width value in image processor is sign extended during conversion to unsigned int, which leads to integer overflow and heap-based ..."}, {"cve": "CVE-2009-0231", "description": "Integer truncation of length value leads to heap-based buffer overflow."}], "platforms": {"languages": ["C", "Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "682": {"name": "Incorrect Calculation", "abstraction": "Pillar", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.", "extended_description": "When product performs a security-critical calculation incorrectly, it might lead to incorrect resource allocations, incorrect privilege assignments, or failed comparisons among other things. Many of the direct results of an incorrect calculation can lead to even larger problems such as failed protection mechanisms or even arbitrary code execution.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (Other)", "Execute Unauthorized Code or Commands"]}, {"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Understand your programming language's underlying representation and how it interacts with numeric calculation. Pay close attention to byte size discrepancies, precision, signed/unsigned distinctions, truncation, conversion and casting between types, \"not-a-number\" calculations, and how your languag...", "phase": ["Implementation"]}, {"description": "Perform input validation on any numeric input by ensuring that it is within the expected range. Enforce that the input meets both the minimum and maximum requirements for the expected range.", "phase": ["Implementation"]}, {"description": "Use the appropriate type for the desired action. For example, in C/C++, only use unsigned types for values that could never be negative, such as height, width, or other numbers related to quantity.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Manual Analysis"}], "observed_examples": [{"cve": "CVE-2020-0022", "description": "chain: mobile phone Bluetooth implementation does not include offset when calculating packet length (CWE-682), leading to out-of-bounds write (CWE-787..."}, {"cve": "CVE-2004-1363", "description": "substitution overflow: buffer overflow using environment variables that are expanded after the length check is performed"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "683": {"name": "Function Call With Incorrect Order of Arguments", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product calls a function, procedure, or routine, but the caller specifies the arguments in an incorrect order, leading to resultant weaknesses.", "extended_description": "While this weakness might be caught by the compiler in some languages, it can occur more frequently in cases in which the called function accepts variable numbers or types of arguments, such as format strings in C. It also can occur in languages or environments that do not enforce strong typing.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "mitigations": [{"description": "Use the function, procedure, or routine as specified.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Analysis", "description": "Because this function call often produces\n\t     incorrect behavior, it will usually be detected during\n\t     testing or normal operation of the product."}, {"method": "Automated Analysis", "description": "Exercising all possible control paths will\n\t     typically expose this weakness, except in rare cases when\n\t     the incorrect function call accidentally produces the\n\t     correct results, or if the ..."}], "observed_examples": [{"cve": "CVE-2006-7049", "description": "Application calls functions with arguments in the wrong order, allowing attacker to bypass intended access restrictions."}], "platforms": {"languages": ["Not Language-Specific"]}}, "684": {"name": "Incorrect Provision of Specified Functionality", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The code does not function according to its published specifications, potentially leading to incorrect usage.", "extended_description": "When providing functionality to an external party, it is important that the product behaves in accordance with the details specified. When requirements of nuances are not documented, the functionality may produce unintended behaviors for the caller, possibly leading to an exploitable state.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "mitigations": [{"description": "Ensure that your code strictly conforms to specifications.", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-1446", "description": "Error checking routine in PKCS#11 library returns \"OK\" status even when invalid signature is detected, allowing spoofed messages."}, {"cve": "CVE-2001-1559", "description": "Chain: System call returns wrong value (CWE-393), leading to a resultant NULL dereference (CWE-476)."}, {"cve": "CVE-2003-0187", "description": "Program uses large timeouts on unconfirmed connections resulting from inconsistency in linked lists implementations."}, {"cve": "CVE-1999-1446", "description": "UI inconsistency; visited URLs list not cleared when \"Clear History\" option is selected."}], "platforms": {"languages": ["Not Language-Specific"]}}, "685": {"name": "Function Call With Incorrect Number of Arguments", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product calls a function, procedure, or routine, but the caller specifies too many arguments, or too few arguments, which may lead to undefined behavior and resultant weaknesses.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "mitigations": [{"description": "Because this function call often produces incorrect behavior it will usually be detected during testing or normal operation of the product. During testing exercise all possible control paths will typically expose this weakness except in rare cases when the incorrect function call accidentally produc...", "phase": ["Testing"]}], "detection_methods": [{"method": "Other", "description": "While this weakness might be caught by the compiler in some languages, it can occur more frequently in cases in which the called function accepts variable numbers of arguments, such as format strings ..."}], "platforms": {"languages": ["C", "Perl"]}}, "686": {"name": "Function Call With Incorrect Argument Type", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product calls a function, procedure, or routine, but the caller specifies an argument that is the wrong data type, which may lead to resultant weaknesses.", "extended_description": "This weakness is most likely to occur in loosely typed languages, or in strongly typed languages in which the types of variable arguments cannot be enforced at compilation time, or where there is implicit casting.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "detection_methods": [{"method": "Other", "description": "Because this function call often produces\n\t     incorrect behavior, it will usually be detected during\n\t     testing or normal operation of the product."}], "platforms": {"languages": ["Not Language-Specific"]}}, "687": {"name": "Function Call With Incorrectly Specified Argument Value", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product calls a function, procedure, or routine, but the caller specifies an argument that contains the wrong value, which may lead to resultant weaknesses.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "detection_methods": [{"method": "Manual Static Analysis", "description": "This might require an understanding of intended program behavior or design to determine whether the value is incorrect."}], "platforms": {"languages": ["Not Language-Specific"]}}, "688": {"name": "Function Call With Incorrect Variable or Reference as Argument", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product calls a function, procedure, or routine, but the caller specifies the wrong variable or reference as one of the arguments, which may lead to undefined behavior and resultant weaknesses.", "consequences": [{"scope": ["Other"], "impact": ["Quality Degradation"]}], "mitigations": [{"description": "Because this function call often produces incorrect behavior it will usually be detected during testing or normal operation of the product. During testing exercise all possible control paths will typically expose this weakness except in rare cases when the incorrect function call accidentally produc...", "phase": ["Testing"]}], "detection_methods": [{"method": "Other", "description": "While this weakness might be caught by the compiler in some languages, it can occur more frequently in cases in which the called function accepts variable numbers of arguments, such as format strings ..."}], "observed_examples": [{"cve": "CVE-2005-2548", "description": "Kernel code specifies the wrong variable in first argument, leading to resultant NULL pointer dereference."}], "platforms": {"languages": ["C", "Perl"]}}, "689": {"name": "Permission Race Condition During Resource Copy", "abstraction": "Compound", "mapping": "ALLOWED", "structure": "Composite", "description": "The product, while copying or cloning a resource, does not set the resource's permissions or access control until the copy is complete, leaving the resource exposed to other spheres while the copy is taking place.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data"]}], "observed_examples": [{"cve": "CVE-2002-0760", "description": "Archive extractor decompresses files with world-readable permissions, then later sets permissions to what the archive specified."}, {"cve": "CVE-2005-2174", "description": "Product inserts a new object into database before setting the object's permissions, introducing a race condition."}, {"cve": "CVE-2006-5214", "description": "Error file has weak permissions before a chmod is performed."}, {"cve": "CVE-2005-2475", "description": "Archive permissions issue using hard link."}, {"cve": "CVE-2003-0265", "description": "Database product creates files world-writable before initializing the setuid bits, leading to modification of executables."}], "platforms": {"languages": ["C", "Perl"]}}, "69": {"name": "Improper Handling of Windows ::DATA Alternate Data Stream", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly prevent access to, or detect usage of, alternate data streams (ADS).", "extended_description": "An attacker can use an ADS to hide information about a file (e.g. size, the name of the process) from a system or file browser tools such as Windows Explorer and 'dir' at the command line utility. Alternately, the attacker might be able to bypass intended access restrictions for the associated data fork.", "consequences": [{"scope": ["Access Control", "Non-Repudiation", "Other"], "impact": ["Bypass Protection Mechanism", "Hide Activities", "Other"]}], "mitigations": [{"description": "Ensure that the source code correctly parses the filename to read or write to the correct stream.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Analysis", "description": "Software tools are capable of finding ADSs on your system."}], "observed_examples": [{"cve": "CVE-1999-0278", "description": "In IIS, remote attackers can obtain source code for ASP files by appending \"::$DATA\" to the URL."}, {"cve": "CVE-2000-0927", "description": "Product does not properly record file sizes if they are stored in alternative data streams, which allows users to bypass quota restrictions."}], "platforms": {"languages": ["Not Language-Specific"]}}, "690": {"name": "Unchecked Return Value to NULL Pointer Dereference", "abstraction": "Compound", "mapping": "DISCOURAGED", "structure": "Chain", "description": "The product does not check for an error after calling a function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference.", "extended_description": "While unchecked return value weaknesses are not limited to returns of NULL pointers (see the examples in CWE-252), functions often return NULL to indicate an error status. When this error condition is not checked, a NULL pointer dereference can occur.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands", "Read Memory", "Modify Memory"]}], "detection_methods": [{"method": "Black Box", "description": "This typically occurs in rarely-triggered error conditions, reducing the chances of detection during black box testing."}, {"method": "White Box", "description": "Code analysis can require knowledge of API behaviors for library functions that might return NULL, reducing the chances of detection when unknown libraries are used."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t      compilation to insert runtime error-checking mechanisms\n\t      related to memory safety errors, such as AddressSanitizer\n\t      (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2008-1052", "description": "Large Content-Length value leads to NULL pointer dereference when malloc fails."}, {"cve": "CVE-2006-6227", "description": "Large message length field leads to NULL pointer dereference when malloc fails."}, {"cve": "CVE-2006-2555", "description": "Parsing routine encounters NULL dereference when input is missing a colon separator."}, {"cve": "CVE-2003-1054", "description": "URI parsing API sets argument to NULL when a parsing failure occurs, such as when the Referer header is missing a hostname, leading to NULL dereferenc..."}, {"cve": "CVE-2008-5183", "description": "chain: unchecked return value can lead to NULL dereference"}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "691": {"name": "Insufficient Control Flow Management", "abstraction": "Pillar", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The code does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.", "consequences": [{"scope": ["Other"], "impact": ["Alter Execution Logic"]}], "observed_examples": [{"cve": "CVE-2024-50653", "description": "e-commerce product does not restrict the number of requests for coupons"}, {"cve": "CVE-2019-9805", "description": "Chain: Creation of the packet client occurs before initialization is complete (CWE-696) resulting in a read from uninitialized memory (CWE-908), causi..."}, {"cve": "CVE-2014-1266", "description": "Chain: incorrect \"goto\" in Apple SSL product bypasses certificate validation, allowing Adversary-in-the-Middle (AITM) attack (Apple \"goto fail\" bug). ..."}, {"cve": "CVE-2011-1027", "description": "Chain: off-by-one error (CWE-193) leads to infinite loop (CWE-835) using invalid hex-encoded characters."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "692": {"name": "Incomplete Denylist to Cross-Site Scripting", "abstraction": "Compound", "mapping": "DISCOURAGED", "structure": "Chain", "description": "The product uses a denylist-based protection mechanism to defend against XSS attacks, but the denylist is incomplete, allowing XSS variants to succeed.", "extended_description": "While XSS might seem simple to prevent, web browsers vary so widely in how they parse web pages, that a denylist cannot keep track of all the variations. The \"XSS Cheat Sheet\" [REF-714] contains a large number of attacks that are intended to bypass incomplete denylists.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "observed_examples": [{"cve": "CVE-2007-5727", "description": "Denylist only removes <SCRIPT> tag."}, {"cve": "CVE-2006-3617", "description": "Denylist only removes <SCRIPT> tag."}, {"cve": "CVE-2006-4308", "description": "Denylist only checks \"javascript:\" tag"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "693": {"name": "Protection Mechanism Failure", "abstraction": "Pillar", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.", "extended_description": "This weakness covers three distinct situations. A \"missing\" protection mechanism occurs when the application does not define any mechanism against a certain class of attack. An \"insufficient\" protection mechanism might provide some defenses - for example, against the most common attacks - but it does not protect against everything that is intended. Finally, an \"ignored\" mechanism occurs when a mechanism is available and in active use within the product, but the developer has not applied it in so...", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "ICS/OT"]}}, "694": {"name": "Use of Multiple Resources with Duplicate Identifier", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses multiple resources that can have the same identifier, in a context in which unique identifiers are required.", "extended_description": "If the product assumes that each resource has a unique identifier, the product could operate on the wrong resource if attackers can cause multiple resources to be associated with the same identifier.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Other"], "impact": ["Quality Degradation"]}], "mitigations": [{"description": "Where possible, use unique identifiers. If non-unique identifiers are detected, then do not operate any resource with a non-unique identifier and report the error appropriately.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2013-4787", "description": "chain: mobile OS verifies cryptographic signature of file in an archive, but then installs a different file with the same name that is also listed in ..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "695": {"name": "Use of Low-Level Functionality", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses low-level functionality that is explicitly prohibited by the framework or specification under which the product is supposed to operate.", "extended_description": "The use of low-level functionality can violate the specification in unexpected ways that effectively disable built-in protection mechanisms, introduce exploitable inconsistencies, or otherwise expose the functionality to attack.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "696": {"name": "Incorrect Behavior Order", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product performs multiple related behaviors, but the behaviors are performed in the wrong order in ways that may produce resultant weaknesses.", "consequences": [{"scope": ["Integrity"], "impact": ["Alter Execution Logic"]}], "observed_examples": [{"cve": "CVE-2019-9805", "description": "Chain: Creation of the packet client occurs before initialization is complete (CWE-696) resulting in a read from uninitialized memory (CWE-908), causi..."}, {"cve": "CVE-2007-5191", "description": "file-system management programs call the setuid and setgid functions in the wrong order and do not check the return values, allowing attackers to gain..."}, {"cve": "CVE-2007-1588", "description": "C++ web server program calls Process::setuid before calling Process::setgid, preventing it from dropping privileges, potentially allowing CGI programs..."}, {"cve": "CVE-2022-37734", "description": "Chain: lexer in Java-based GraphQL server does not enforce maximum of tokens early enough (CWE-696), allowing excessive CPU consumption (CWE-1176)"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based"]}}, "697": {"name": "Incorrect Comparison", "abstraction": "Pillar", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product compares two entities in a security-relevant context, but the comparison is incorrect.", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2021-3116", "description": "Chain: Python-based HTTP Proxy server uses the wrong boolean operators (CWE-480) causing an  incorrect comparison (CWE-697) that identifies an authN f..."}, {"cve": "CVE-2020-15811", "description": "Chain: Proxy uses a substring search instead of parsing the Transfer-Encoding header (CWE-697), allowing request splitting (CWE-113) and cache poisoni..."}, {"cve": "CVE-2016-10003", "description": "Proxy performs incorrect comparison of request headers, leading to infoleak"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "698": {"name": "Execution After Redirect (EAR)", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The web application sends a redirect to another location, but instead of exiting, it executes additional code.", "consequences": [{"scope": ["Other", "Confidentiality", "Integrity", "Availability"], "impact": ["Alter Execution Logic", "Execute Unauthorized Code or Commands"]}], "detection_methods": [{"method": "Black Box", "description": "This issue might not be detected if testing is performed using a web browser, because the browser might obey the redirect and move the user to a different page before the application has produced outp..."}], "observed_examples": [{"cve": "CVE-2013-1402", "description": "Execution-after-redirect allows access to application configuration details."}, {"cve": "CVE-2009-1936", "description": "chain: library file sends a redirect if it is directly requested but continues to execute, allowing remote file inclusion and path traversal."}, {"cve": "CVE-2007-2713", "description": "Remote attackers can obtain access to administrator functionality through EAR."}, {"cve": "CVE-2007-4932", "description": "Remote attackers can obtain access to administrator functionality through EAR."}, {"cve": "CVE-2007-5578", "description": "Bypass of authentication step through EAR."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "7": {"name": "J2EE Misconfiguration: Missing Custom Error Page", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The default error page of a web application should not display sensitive information about the product.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "mitigations": [{"description": "Handle exceptions appropriately in source code.", "phase": ["Implementation"]}, {"description": "Always define appropriate error pages. The application configuration should specify a default error page in order to guarantee that the application will never leak error messages to an attacker. Handling standard HTTP error codes is useful and user-friendly in addition to being a good security pract...", "phase": ["Implementation", "System Configuration"]}, {"description": "Do not attempt to process an error or attempt to mask it.", "phase": ["Implementation"]}], "platforms": {"languages": ["Java"], "technologies": ["Web Based", "Web Server"]}}, "703": {"name": "Improper Check or Handling of Exceptional Conditions", "abstraction": "Pillar", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.", "consequences": [{"scope": ["Confidentiality", "Availability", "Integrity"], "impact": ["Read Application Data", "DoS: Crash, Exit, or Restart", "Unexpected State"]}], "detection_methods": [{"method": "Dynamic Analysis with Manual Results Interpretation"}, {"method": "Manual Static Analysis - Source Code"}, {"method": "Automated Static Analysis - Source Code"}], "observed_examples": [{"cve": "[REF-1374]", "description": "Chain: JavaScript-based cryptocurrency library can fall back to the insecure Math.random() function instead of reporting a failure (CWE-392), thus red..."}, {"cve": "CVE-2022-22224", "description": "Chain: an operating system does not properly process malformed Open Shortest Path First (OSPF) Type/Length/Value Identifiers (TLV) (CWE-703), which ca..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "704": {"name": "Incorrect Type Conversion or Cast", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not correctly convert an object, resource, or structure from one type to a different type.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}], "observed_examples": [{"cve": "CVE-2021-43537", "description": "Chain: in a web browser, an unsigned 64-bit integer is forcibly cast to a 32-bit integer (CWE-681) and potentially leading to an integer overflow (CWE..."}, {"cve": "CVE-2022-3979", "description": "Chain: data visualization program written in PHP uses the \"!=\" operator instead of the type-strict \"!==\" operator (CWE-480) when validating hash value..."}], "platforms": {"languages": ["C", "C++", "Not Language-Specific", "Memory-Unsafe"], "technologies": ["Not Technology-Specific"]}}, "705": {"name": "Incorrect Control Flow Scoping", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not properly return control flow to the proper location after it has completed a task or detected an unusual condition.", "consequences": [{"scope": ["Other"], "impact": ["Alter Execution Logic", "Other"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2023-21087", "description": "Java code in a smartphone OS can encounter a \"boot loop\" due to an uncaught exception"}, {"cve": "CVE-2014-1266", "description": "Chain: incorrect \"goto\" in Apple SSL product bypasses certificate validation, allowing Adversary-in-the-Middle (AITM) attack (Apple \"goto fail\" bug). ..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "706": {"name": "Use of Incorrectly-Resolved Name or Reference", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "707": {"name": "Improper Neutralization", "abstraction": "Pillar", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "708": {"name": "Incorrect Ownership Assignment", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product assigns an owner to a resource, but the owner is outside of the intended control sphere.", "extended_description": "This may allow the resource to be manipulated by actors outside of the intended control sphere.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data"]}], "mitigations": [{"description": "Periodically review the privileges and their owners.", "phase": ["Policy"]}], "detection_methods": [{"method": "Automated Analysis", "description": "Use automated tools to check for privilege settings."}], "observed_examples": [{"cve": "CVE-2024-43199", "description": "product installs binaries with potentially insecure user/group ownership"}, {"cve": "CVE-2007-5101", "description": "File system sets wrong ownership and group when creating a new file."}, {"cve": "CVE-2007-4238", "description": "OS installs program with bin owner/group, allowing modification."}, {"cve": "CVE-2007-1716", "description": "Manager does not properly restore ownership of a reusable resource when a user logs out, allowing privilege escalation."}, {"cve": "CVE-2005-3148", "description": "Backup software restores symbolic links with incorrect uid/gid."}], "platforms": {"languages": ["Not Language-Specific"]}}, "71": {"name": "DEPRECATED: Apple '.DS_Store'", "abstraction": "Variant", "mapping": "PROHIBITED", "structure": "Simple", "description": "This entry has been deprecated as it represents a specific observed example of a UNIX Hard Link weakness type rather than its own individual weakness type. Please refer to CWE-62."}, "710": {"name": "Improper Adherence to Coding Standards", "abstraction": "Pillar", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "mitigations": [{"description": "Select and require coding\n               standards. Ensure that they include security\n               concerns.", "phase": ["Policy"]}, {"description": "Closely follow coding standards, possibly\n               enforcing them upon checkin of the code into a source\n               control system or with periodic analyses.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated tools can detect violations of many code standards."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "72": {"name": "Improper Handling of Apple HFS+ Alternate Data Stream Path", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly handle special paths that may identify the data or resource fork of a file on the HFS+ file system.", "extended_description": "If the product chooses actions to take based on the file name, then if an attacker provides the data or resource fork, the product may take unexpected actions. Further, if the product intends to restrict access to a file, then an attacker might still be able to bypass intended access restrictions by requesting the data or resource fork for that file.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}], "observed_examples": [{"cve": "CVE-2004-1084", "description": "Server allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data stream..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "73": {"name": "External Control of File Name or Path", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product allows user input to control or influence paths or file names that are used in filesystem operations.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality"], "impact": ["Read Files or Directories", "Modify Files or Directories"]}, {"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Modify Files or Directories", "Execute Unauthorized Code or Commands"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (Other)"]}], "mitigations": [{"description": "When the set of filenames is limited or known, create a mapping from a set of fixed input values (such as numeric IDs) to the actual filenames, and reject all other inputs. For example, ID 1 could map to \"inbox.txt\" and ID 2 could map to \"profile.txt\". Features such as the ESAPI AccessReferenceMap p...", "phase": ["Architecture and Design"]}, {"description": "For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-s...", "phase": ["Architecture and Design"]}, {"description": "Use a built-in path canonicalization function (such as realpath() in C) that produces the canonical version of the pathname, which effectively removes \"..\" sequences and symbolic links (CWE-23, CWE-59).", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis"}], "observed_examples": [{"cve": "CVE-2022-45918", "description": "Chain: a learning management tool debugger uses external input to locate previous session logs (CWE-73) and does not properly validate the given path ..."}, {"cve": "CVE-2008-5748", "description": "Chain: external control of values for user's desired language and theme enables path traversal."}, {"cve": "CVE-2008-5764", "description": "Chain: external control of user's target language enables remote file inclusion."}], "platforms": {"languages": ["Not Language-Specific"]}}, "732": {"name": "Incorrect Permission Assignment for Critical Resource", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.", "extended_description": "When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data", "Read Files or Directories"]}, {"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Integrity", "Other"], "impact": ["Modify Application Data", "Other"]}], "mitigations": [{"description": "When using a critical resource such as a configuration file, check to see if the resource has insecure permissions (such as being modifiable by any regular user) [REF-62], and generate an error or even exit the software if there is a possibility that the resource could have been modified by an unaut...", "phase": ["Implementation"]}, {"description": "Divide the software into anonymous, normal, privileged, and administrative areas. Reduce the attack surface by carefully defining distinct user groups, privileges, and/or roles. Map these against data, functionality, and the related resources. Then set the permissions accordingly. This will allow yo...", "phase": ["Architecture and Design"]}, {"description": "During program startup, explicitly set the default permissions or umask to the most restrictive setting possible. Also set the appropriate permissions during program installation. This will prevent you from inheriting insecure permissions from any user who installs or runs the program.", "phase": ["Implementation", "Installation"]}], "detection_methods": [{"method": "Automated Static Analysis"}, {"method": "Automated Dynamic Analysis"}, {"method": "Manual Analysis", "description": "This weakness can be detected using tools and techniques that require manual (human) analysis, such as penetration testing, threat modeling, and interactive tools that allow the tester to record and m..."}], "observed_examples": [{"cve": "CVE-2022-29527", "description": "Go application for cloud management creates a world-writable sudoers file that allows local attackers to inject sudo rules and escalate privileges to ..."}, {"cve": "CVE-2009-3482", "description": "Anti-virus product sets insecure \"Everyone: Full Control\" permissions for files under the \"Program Files\" folder, allowing attackers to replace execut..."}, {"cve": "CVE-2009-3897", "description": "Product creates directories with 0777 permissions at installation, allowing users to gain privileges and access a socket used for authentication."}, {"cve": "CVE-2009-3489", "description": "Photo editor installs a service with an insecure security descriptor, allowing users to stop or start the service, or execute commands as SYSTEM."}, {"cve": "CVE-2020-15708", "description": "socket created with insecure permissions"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Cloud Computing"]}}, "733": {"name": "Compiler Optimization Removal or Modification of Security-critical Code", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The developer builds a security-critical protection mechanism into the software, but the compiler optimizes the program such that the mechanism is removed or modified.", "consequences": [{"scope": ["Access Control", "Other"], "impact": ["Bypass Protection Mechanism", "Alter Execution Logic"]}], "detection_methods": [{"method": "Black Box", "description": "This specific weakness is impossible to detect using black box methods. While an analyst could examine memory to see that it has not been scrubbed, an analysis of the executable would not be successfu..."}, {"method": "White Box", "description": "This weakness is only detectable using white box methods (see black box detection factor). Careful analysis is required to determine if the code is likely to be removed by the compiler."}], "observed_examples": [{"cve": "CVE-2008-1685", "description": "C compiler optimization, as allowed by specifications, removes code that is used to perform checks to detect integer overflows."}, {"cve": "CVE-2019-1010006", "description": "Chain: compiler optimization (CWE-733) removes or modifies code used to detect integer overflow (CWE-190), allowing out-of-bounds write (CWE-787)."}], "platforms": {"languages": ["C", "C++", "Compiled"]}}, "74": {"name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Other"], "impact": ["Alter Execution Logic"]}, {"scope": ["Integrity", "Other"], "impact": ["Other"]}, {"scope": ["Non-Repudiation"], "impact": ["Hide Activities"]}], "mitigations": [{"description": "Programming languages and supporting technologies might be chosen which are not subject to these issues.", "phase": ["Requirements"]}, {"description": "Utilize an appropriate mix of allowlist and denylist parsing to filter control-plane syntax from all input.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2024-5184", "description": "API service using a large generative AI model allows direct prompt injection to leak hard-coded system prompts or execute other prompts."}, {"cve": "CVE-2022-36069", "description": "Python-based dependency management tool avoids OS command injection  when generating Git commands but allows  injection of optional arguments with inp..."}, {"cve": "CVE-1999-0067", "description": "Canonical example of OS command injection. CGI program does not neutralize \"|\" metacharacter when invoking a phonebook program."}, {"cve": "CVE-2022-1509", "description": "injection of sed script syntax (\"sed injection\")"}, {"cve": "CVE-2020-9054", "description": "Chain: improper input validation (CWE-20) in username parameter, leading to OS command injection (CWE-78), as exploited in the wild per CISA KEV."}], "platforms": {"languages": ["Not Language-Specific"]}}, "749": {"name": "Exposed Dangerous Method or Function", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability", "Access Control", "Other"], "impact": ["Gain Privileges or Assume Identity", "Read Application Data", "Modify Application Data", "Execute Unauthorized Code or Commands", "Other"]}], "mitigations": [{"description": "If you must expose a method, make sure to perform input validation on all arguments, limit access to authorized parties, and protect against all possible vulnerabilities.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2007-6382", "description": "arbitrary Java code execution via exposed method"}, {"cve": "CVE-2007-1112", "description": "security tool ActiveX control allows download or upload of files"}], "platforms": {"languages": ["Not Language-Specific"]}}, "75": {"name": "Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not adequately filter user-controlled input for special elements with control implications.", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Modify Application Data", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Programming languages and supporting technologies might be chosen which are not subject to these issues.", "phase": ["Requirements"]}, {"description": "Utilize an appropriate mix of allowlist and denylist parsing to filter special element syntax from all input.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "754": {"name": "Improper Check for Unusual or Exceptional Conditions", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Integrity", "Availability"], "impact": ["DoS: Crash, Exit, or Restart", "Unexpected State"]}], "mitigations": [{"description": "Check the results of all functions that return a value and verify that the value is expected.", "phase": ["Implementation"]}, {"description": "If using exception handling, catch and throw specific exceptions instead of overly-general exceptions (CWE-396, CWE-397). Catch and handle exceptions as locally as possible so that exceptions do not propagate too far up the call stack (CWE-705). Avoid unchecked or uncaught exceptions where feasible ...", "phase": ["Implementation"]}, {"description": "If the program must fail, ensure that it fails gracefully (fails closed). There may be a temptation to simply let the program fail poorly in cases such as low memory conditions, but an attacker may be able to assert control before the software has fully exited. Alternately, an uncontrolled failure c...", "phase": ["Architecture and Design", "Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis may be useful for detecting unusual conditions involving system resources or common programming idioms, but not for violations of business rules."}, {"method": "Manual Dynamic Analysis", "description": "Identify error conditions that are not likely to occur during normal usage and trigger them. For example, run the program under low memory conditions, run with insufficient privileges or permissions, ..."}], "observed_examples": [{"cve": "CVE-2023-49286", "description": "Chain: function in web caching proxy does not correctly check a return value (CWE-253) leading to a reachable assertion (CWE-617)"}, {"cve": "CVE-2007-3798", "description": "Unchecked return value leads to resultant integer overflow and code execution."}, {"cve": "CVE-2006-4447", "description": "Program does not check return value when invoking functions to drop privileges, which could leave users with higher privileges than expected by forcin..."}, {"cve": "CVE-2006-2916", "description": "Program does not check return value when invoking functions to drop privileges, which could leave users with higher privileges than expected by forcin..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "755": {"name": "Improper Handling of Exceptional Conditions", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product does not handle or incorrectly handles an exceptional condition.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2023-41151", "description": "SDK for OPC Unified Architecture (OPC UA) server has uncaught exception when a socket is blocked for writing but the server tries to send an error"}, {"cve": "[REF-1374]", "description": "Chain: JavaScript-based cryptocurrency library can fall back to the insecure Math.random() function instead of reporting a failure (CWE-392), thus red..."}, {"cve": "CVE-2021-3011", "description": "virtual interrupt controller in a virtualization product allows crash of host by writing a certain invalid value to a register, which triggers a fatal..."}, {"cve": "CVE-2008-4302", "description": "Chain: OS kernel does not properly handle a failure of a function call (CWE-755), leading to an unlock of a resource that was not locked (CWE-832), wi..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "756": {"name": "Missing Custom Error Page", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not return custom error pages to the user, possibly exposing sensitive information.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Server"]}}, "757": {"name": "Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "A protocol or its implementation supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties.", "extended_description": "When a security mechanism can be forced to downgrade to use a less secure algorithm, this can make it easier for attackers to compromise the product by exploiting weaker algorithm. The victim might not be aware that the less secure algorithm is being used. For example, if an attacker can force a communications channel to use cleartext instead of strongly-encrypted data, then the attacker could read the channel by sniffing, instead of going through extra effort of trying to decrypt the data using...", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2006-4302", "description": "Attacker can select an older version of the software to exploit its vulnerabilities."}, {"cve": "CVE-2006-4407", "description": "Improper prioritization of encryption ciphers during negotiation leads to use of a weaker cipher."}, {"cve": "CVE-2005-2969", "description": "chain: SSL/TLS implementation disables a verification step (CWE-325) that enables a downgrade attack to a weaker protocol."}, {"cve": "CVE-2001-1444", "description": "Telnet protocol implementation allows downgrade to weaker authentication and encryption using an Adversary-in-the-Middle AITM attack."}, {"cve": "CVE-2002-1646", "description": "SSH server implementation allows override of configuration setting to use weaker authentication schemes. This may be a composite with CWE-642."}], "platforms": {"languages": ["Not Language-Specific"]}}, "758": {"name": "Reliance on Undefined, Unspecified, or Implementation-Defined Behavior", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product uses an API function, data structure, or other entity in a way that relies on properties that are not always guaranteed to hold for that entity.", "extended_description": "This can lead to resultant weaknesses when the required properties change, such as when the product is ported to a different platform or if an interaction error (CWE-435) occurs.", "consequences": [{"scope": ["Other"], "impact": ["Reduce Maintainability", "Unexpected State", "Quality Degradation"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}], "observed_examples": [{"cve": "CVE-2006-1902", "description": "Change in C compiler behavior causes resultant buffer overflows in programs that depend on behaviors that were undefined in the C standard."}], "platforms": {"languages": ["Not Language-Specific"]}}, "759": {"name": "Use of a One-Way Hash without a Salt", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "If a technique that requires extra computational effort can not be implemented, then for each password that is processed, generate a new random salt using a strong random number generator with unpredictable seeds. Add the salt to the plaintext password before hashing it. When storing the hash, also ...", "phase": ["Architecture and Design"]}, {"description": "When using industry-approved techniques, use them correctly. Don't cut corners by skipping resource-intensive steps (CWE-325). These steps are often essential for preventing common attacks.", "phase": ["Implementation", "Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Manual Static Analysis - Binary or Bytecode"}, {"method": "Manual Static Analysis - Source Code"}], "observed_examples": [{"cve": "CVE-2008-1526", "description": "Router does not use a salt with a hash, making it easier to crack passwords."}, {"cve": "CVE-2006-1058", "description": "Router does not use a salt with a hash, making it easier to crack passwords."}], "platforms": {"languages": ["Not Language-Specific"]}}, "76": {"name": "Improper Neutralization of Equivalent Special Elements", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product correctly neutralizes certain special elements, but it improperly neutralizes equivalent special elements.", "extended_description": "The product may have a fixed list of special characters it believes is complete. However, there may be alternate encodings, or representations that also have the same meaning. For example, the product may filter out a leading slash (/) to prevent absolute path names, but does not account for a tilde (~) followed by a user name, which on some *nix systems could be expanded to an absolute pathname. Alternately, the product might filter a dangerous \"-e\" command-line switch when calling an external ...", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "mitigations": [{"description": "Programming languages and supporting technologies might be chosen which are not subject to these issues.", "phase": ["Requirements"]}, {"description": "Utilize an appropriate mix of allowlist and denylist parsing to filter equivalent special element syntax from all input.", "phase": ["Implementation"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "760": {"name": "Use of a One-Way Hash with a Predictable Salt", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product uses a predictable salt as part of the input.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "If a technique that requires extra computational effort can not be implemented, then for each password that is processed, generate a new random salt using a strong random number generator with unpredictable seeds. Add the salt to the plaintext password before hashing it. When storing the hash, also ...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2008-4905", "description": "Blogging software uses a hard-coded salt when calculating a password hash."}, {"cve": "CVE-2002-1657", "description": "Database server uses the username for a salt when encrypting passwords, simplifying brute force attacks."}, {"cve": "CVE-2001-0967", "description": "Server uses a constant salt when encrypting passwords, simplifying brute force attacks."}, {"cve": "CVE-2005-0408", "description": "chain: product generates predictable MD5 hashes using a constant value combined with username, allowing authentication bypass."}], "platforms": {"languages": ["Not Language-Specific"]}}, "761": {"name": "Free of Pointer not at Start of Buffer", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product calls free() on a pointer to a memory resource that was allocated on the heap, but the pointer is not at the start of the buffer.", "consequences": [{"scope": ["Integrity", "Availability", "Confidentiality"], "impact": ["Modify Memory", "DoS: Crash, Exit, or Restart", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "When utilizing pointer arithmetic to traverse a buffer, use a separate variable to track progress through memory and preserve the originally allocated address for later freeing.", "phase": ["Implementation"]}, {"description": "When programming in C++, consider using smart pointers provided by the boost library to help correctly and consistently manage memory.", "phase": ["Implementation"]}, {"description": "Use a language that provides abstractions for memory allocation and deallocation.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Dynamic Analysis with Automated Results Interpretation", "description": "Use a tool that dynamically detects memory\n\t     management problems, such as valgrind."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2019-11930", "description": "function \"internally calls 'calloc' and returns a pointer at an index... inside the allocated buffer. This led to freeing invalid memory.\""}], "platforms": {"languages": ["Memory-Unsafe", "C"]}}, "762": {"name": "Mismatched Memory Management Routines", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product attempts to return a memory resource to the system, but it calls a release function that is not compatible with the function that was originally used to allocate that resource.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Integrity", "Availability", "Confidentiality"], "impact": ["Modify Memory", "DoS: Crash, Exit, or Restart", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Only call matching memory management functions. Do not mix and match routines. For example, when you allocate a buffer with malloc(), dispose of the original pointer with free().", "phase": ["Implementation"]}, {"description": "Use a language that provides abstractions for memory allocation and deallocation.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Dynamic Analysis with Automated Results Interpretation", "description": "Use a tool that dynamically detects memory\n\t     management problems, such as valgrind."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "763": {"name": "Release of Invalid Pointer or Reference", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product attempts to return a memory resource to the system, but it calls the wrong release function or calls the appropriate release function incorrectly.", "consequences": [{"scope": ["Integrity", "Availability", "Confidentiality"], "impact": ["Modify Memory", "DoS: Crash, Exit, or Restart", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Only call matching memory management functions. Do not mix and match routines. For example, when you allocate a buffer with malloc(), dispose of the original pointer with free().", "phase": ["Implementation"]}, {"description": "When programming in C++, consider using smart pointers provided by the boost library to help correctly and consistently manage memory.", "phase": ["Implementation"]}, {"description": "Use a language that provides abstractions for memory allocation and deallocation.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2019-11930", "description": "function \"internally calls 'calloc' and returns a pointer at an index... inside the allocated buffer. This led to freeing invalid memory.\""}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "764": {"name": "Multiple Locks of a Critical Resource", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product locks a critical resource more times than intended, leading to an unexpected state in the system.", "extended_description": "When a product is operating in a concurrent environment and repeatedly locks a critical resource, the consequences will vary based on the type of lock, the lock's implementation, and the resource being protected. In some situations such as with semaphores, the resources are pooled and extra locking calls will reduce the size of the total available pool, possibly leading to degraded performance or a denial of service. If this can be triggered by an attacker, it will be similar to an unrestricted ...", "consequences": [{"scope": ["Availability", "Integrity"], "impact": ["DoS: Resource Consumption (CPU)", "DoS: Crash, Exit, or Restart", "Unexpected State"]}], "mitigations": [{"description": "When locking and unlocking a resource, try to be sure that all control paths through the code in which the resource is locked one or more times correspond to exactly as many unlocks. If the software acquires a lock and then determines it is not able to perform its intended behavior, be sure to relea...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "765": {"name": "Multiple Unlocks of a Critical Resource", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product unlocks a critical resource more times than intended, leading to an unexpected state in the system.", "extended_description": "When the product is operating in a concurrent environment and repeatedly unlocks a critical resource, the consequences will vary based on the type of lock, the lock's implementation, and the resource being protected. In some situations such as with semaphores, the resources are pooled and extra calls to unlock will increase the count for the number of available resources, likely resulting in a crash or unpredictable behavior when the system nears capacity.", "consequences": [{"scope": ["Availability", "Integrity"], "impact": ["DoS: Crash, Exit, or Restart", "Modify Memory", "Unexpected State"]}], "mitigations": [{"description": "When locking and unlocking a resource, try to be sure that all control paths through the code in which the resource is locked one or more times correspond to exactly as many unlocks. If the product acquires a lock and then determines it is not able to perform its intended behavior, be sure to releas...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2009-0935", "description": "Attacker provides invalid address to a memory-reading function, causing a mutex to be unlocked twice"}], "platforms": {"languages": ["Not Language-Specific"]}}, "766": {"name": "Critical Data Element Declared Public", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product declares a critical variable, field, or member to be public when intended security policy requires it to be private.", "consequences": [{"scope": ["Integrity", "Confidentiality"], "impact": ["Read Application Data", "Modify Application Data"]}, {"scope": ["Other"], "impact": ["Reduce Maintainability"]}], "mitigations": [{"description": "Data should be private, static, and final whenever possible. This will assure that your code is protected by instantiating early, preventing access, and preventing tampering.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2010-3860", "description": "variables declared public allow remote read of system properties such as user name and home directory."}], "platforms": {"languages": ["C++", "C#", "Java"]}}, "767": {"name": "Access to Critical Private Variable via Public Method", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product defines a public method that reads or modifies a private variable.", "extended_description": "If an attacker modifies the variable to contain unexpected values, this could violate assumptions from other parts of the code. Additionally, if an attacker can read the private variable, it may expose sensitive information or make it easier to launch further attacks.", "consequences": [{"scope": ["Integrity", "Other"], "impact": ["Modify Application Data", "Other"]}], "mitigations": [{"description": "Use class accessor and mutator methods appropriately. Perform validation when accepting data from a public method that is intended to modify a critical private variable. Also be sure that appropriate access controls are being applied when a public method interfaces with critical data.", "phase": ["Implementation"]}], "platforms": {"languages": ["C++", "C#", "Java"]}}, "768": {"name": "Incorrect Short Circuit Evaluation", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains a conditional statement with multiple logical expressions in which one of the non-leading expressions may produce side effects. This may lead to an unexpected state in the program after the execution of the conditional, because short-circuiting logic may prevent the side effects from occurring.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "Minimizing the number of statements in a conditional that produce side effects will help to prevent the likelihood of short circuit evaluation to alter control flow in an unexpected way.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific", "C"]}}, "769": {"name": "DEPRECATED: Uncontrolled File Descriptor Consumption", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "This entry has been deprecated because it was a duplicate of CWE-774. All content has been transferred to CWE-774."}, "77": {"name": "Improper Neutralization of Special Elements used in a Command ('Command Injection')", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "If at all possible, use library calls rather than external processes to recreate the desired functionality.", "phase": ["Architecture and Design"]}, {"description": "If possible, ensure that all external commands called from the program are statically created.", "phase": ["Implementation"]}, {"description": "Run time: Run time policy enforcement may be used in an allowlist fashion to prevent use of any non-sanctioned commands.", "phase": ["Operation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-1509", "description": "injection of sed script syntax (\"sed injection\")"}, {"cve": "CVE-2024-5184", "description": "API service using a large generative AI model allows direct prompt injection to leak hard-coded system prompts or execute other prompts."}, {"cve": "CVE-2020-11698", "description": "anti-spam product allows injection of SNMP commands into confiuration file"}, {"cve": "CVE-2019-12921", "description": "image program allows injection of commands in \"Magick Vector Graphics (MVG)\" language."}, {"cve": "CVE-2022-36069", "description": "Python-based dependency management tool avoids OS command injection when generating Git commands but allows injection of optional arguments with input..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["AI/ML"]}}, "770": {"name": "Allocation of Resources Without Limits or Throttling", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Resource Consumption (Other)"]}], "mitigations": [{"description": "Clearly specify the minimum and maximum expectations for capabilities, and dictate which behaviors are acceptable when resource allocation reaches limits.", "phase": ["Requirements"]}, {"description": "Limit the amount of resources that are accessible to unprivileged users. Set per-user limits for resources. Allow the system administrator to define these limits. Be careful to avoid CWE-410.", "phase": ["Architecture and Design"]}, {"description": "Design throttling mechanisms into the system architecture. The best protection is to limit the amount of resources that an unauthorized user can cause to be expended. A strong authentication and access control model will help prevent such attacks from occurring in the first place, and it will help t...", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Manual Static Analysis", "description": "Manual static analysis can be useful for finding this weakness, but it might not achieve desired code coverage within limited time constraints. If denial-of-service is not considered a significant ris..."}, {"method": "Fuzzing"}, {"method": "Automated Dynamic Analysis", "description": "Certain automated dynamic analysis techniques may be effective in producing side effects of uncontrolled resource allocation problems, especially with resources such as processes, memory, and connecti..."}], "observed_examples": [{"cve": "CVE-2019-19911", "description": "Chain: Python library does not limit the resources used to process images that specify a very large number of bands (CWE-1284), leading to excessive m..."}, {"cve": "CVE-2009-4017", "description": "Language interpreter does not restrict the number of temporary files being created when handling a MIME request with a large number of parts.."}, {"cve": "CVE-2009-2726", "description": "Driver does not use a maximum width when invoking sscanf style functions, causing stack consumption."}, {"cve": "CVE-2009-2540", "description": "Large integer value for a length property in an object causes a large amount of memory allocation."}, {"cve": "CVE-2009-2054", "description": "Product allows exhaustion of file descriptors when processing a large number of TCP packets."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "771": {"name": "Missing Reference to Active Allocated Resource", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly maintain a reference to a resource that has been allocated, which prevents the resource from being reclaimed.", "extended_description": "This does not necessarily apply in languages or frameworks that automatically perform garbage collection, since the removal of all references may act as a signal that the resource is ready to be reclaimed.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (Other)"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "772": {"name": "Missing Release of Resource after Effective Lifetime", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (Other)", "DoS: Resource Consumption (Memory)", "DoS: Resource Consumption (CPU)"]}], "mitigations": [{"description": "It is good practice to be responsible for freeing all resources you allocate and to be consistent with how and where you free resources in a function. If you allocate resources that you intend to free upon completion of the function, you must be sure to free the resources at all exit points for that...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2007-0897", "description": "Chain: anti-virus product encounters a malformed file but returns from a function without closing a file descriptor (CWE-775) leading to file descript..."}, {"cve": "CVE-2001-0830", "description": "Sockets not properly closed when attacker repeatedly connects and disconnects from server."}, {"cve": "CVE-1999-1127", "description": "Does not shut down named pipe connections if malformed data is sent."}, {"cve": "CVE-2009-2858", "description": "Chain: memory leak (CWE-404) leads to resource exhaustion."}, {"cve": "CVE-2009-2054", "description": "Product allows exhaustion of file descriptors when processing a large number of TCP packets."}], "platforms": {"technologies": ["Mobile"]}}, "773": {"name": "Missing Reference to Active File Descriptor or Handle", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly maintain references to a file descriptor or handle, which prevents that file descriptor/handle from being reclaimed.", "extended_description": "This can cause the product to consume all available file descriptors or handles, which can prevent other processes from performing critical file processing operations.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (Other)"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "774": {"name": "Allocation of File Descriptors or Handles Without Limits or Throttling", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product allocates file descriptors or handles on behalf of an actor without imposing any restrictions on how many descriptors can be allocated, in violation of the intended security policy for that actor.", "extended_description": "This can cause the product to consume all available file descriptors or handles, which can prevent other processes from performing critical file processing operations.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (Other)"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "775": {"name": "Missing Release of File Descriptor or Handle after Effective Lifetime", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not release a file descriptor or handle after its effective lifetime has ended, i.e., after the file descriptor/handle is no longer needed.", "extended_description": "When a file descriptor or handle is not released after use (typically by explicitly closing it), attackers can cause a denial of service by consuming all available file descriptors/handles, or otherwise preventing other system processes from obtaining their own file descriptors/handles.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (Other)"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2007-0897", "description": "Chain: anti-virus product encounters a malformed file but returns from a function without closing a file descriptor (CWE-775) leading to file descript..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "776": {"name": "Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.", "extended_description": "If the DTD contains a large number of nested or recursive entities, this can lead to explosive growth of data when parsed, causing a denial of service.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (Other)"]}], "mitigations": [{"description": "If possible, prohibit the use of DTDs or use an XML parser that limits the expansion of recursive DTD entities.", "phase": ["Operation"]}, {"description": "Before parsing XML files with associated DTDs, scan for recursive entity declarations and do not continue parsing potentially explosive content.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2008-3281", "description": "XEE in XML-parsing library."}, {"cve": "CVE-2011-3288", "description": "XML bomb / XEE in enterprise communication product."}, {"cve": "CVE-2011-1755", "description": "\"Billion laughs\" attack in XMPP server daemon."}, {"cve": "CVE-2009-1955", "description": "XML bomb in web server module"}, {"cve": "CVE-2003-1564", "description": "Parsing library allows XML bomb"}], "platforms": {"languages": ["Not Language-Specific", "XML"], "technologies": ["Not Technology-Specific"]}}, "777": {"name": "Regular Expression without Anchors", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a regular expression to perform neutralization, but the regular expression is not anchored and may allow malicious or malformed data to slip through.", "extended_description": "When performing tasks such as validating against a set of allowed inputs (allowlist), data is examined and possibly modified to ensure that it is well-formed and adheres to a list of safe values. If the regular expression is not anchored, malicious or malformed data may be included before or after any string matching the regular expression. The type of malicious data that is allowed will depend on the context of the application and which anchors are omitted from the regular expression.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Availability", "Confidentiality", "Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Be sure to understand both what will be matched and what will not be matched by a regular expression. Anchoring the ends of the expression will allow the programmer to define an allowlist strictly limited to what is matched by the text in the regular expression. If you are using a package that only ...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2022-30034", "description": "Chain: Web UI for a Python RPC framework does not use regex anchors to validate user login emails (CWE-777), potentially allowing bypass of OAuth (CWE..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "778": {"name": "Insufficient Logging", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "When a security-critical event occurs, the product either does not record the event or omits important details about the event when logging it.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Non-Repudiation"], "impact": ["Hide Activities"]}], "mitigations": [{"description": "Use a centralized logging mechanism that supports multiple levels of detail.", "phase": ["Architecture and Design"]}, {"description": "Ensure that all security-related successes and failures can be logged. When storing data in the cloud (e.g., AWS S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to enable and capture detailed logging information.", "phase": ["Implementation"]}, {"description": "Be sure to set the level of logging appropriately in a production environment. Sufficient data should be logged to enable system administrators to detect attacks, diagnose errors, and recover from attacks. At the same time, logging too much data (CWE-779) can cause the same problems, including unexp...", "phase": ["Operation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2008-4315", "description": "server does not log failed authentication attempts, making it easier for attackers to perform brute force password guessing without being detected"}, {"cve": "CVE-2008-1203", "description": "admin interface does not log failed authentication attempts, making it easier for attackers to perform brute force password guessing without being det..."}, {"cve": "CVE-2007-3730", "description": "default configuration for POP server does not log source IP or username for login attempts"}, {"cve": "CVE-2007-1225", "description": "proxy does not log requests without \"http://\" in the URL, allowing web surfers to access restricted web content without detection"}, {"cve": "CVE-2003-1566", "description": "web server does not log requests for a non-standard request type"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Cloud Computing", "Not Technology-Specific"]}}, "779": {"name": "Logging of Excessive Data", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product logs too much information, making log files hard to process and possibly hindering recovery efforts or forensic analysis after an attack.", "extended_description": "While logging is a good practice in general, and very high levels of logging are appropriate for debugging stages of development, too much logging in a production environment might hinder a system administrator's ability to detect anomalous conditions. This can provide cover for an attacker while attempting to penetrate a system, clutter the audit trail for forensic analysis, or make it more difficult to debug problems in a production environment.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Other)"]}, {"scope": ["Non-Repudiation"], "impact": ["Hide Activities"]}, {"scope": ["Non-Repudiation"], "impact": ["Hide Activities"]}], "mitigations": [{"description": "Suppress large numbers of duplicate log messages and replace them with periodic summaries. For example, syslog may include an entry that states \"last message repeated X times\" when recording repeated events.", "phase": ["Architecture and Design"]}, {"description": "Support a maximum size for the log file that can be controlled by the administrator. If the maximum size is reached, the admin should be notified. Also, consider reducing functionality of the product. This may result in a denial-of-service to legitimate product users, but it will prevent the product...", "phase": ["Architecture and Design"]}, {"description": "Adjust configurations appropriately when the product is transitioned from a debug state to production.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2007-0421", "description": "server records a large amount of data to the server log when it receives malformed headers"}, {"cve": "CVE-2002-1154", "description": "chain: application does not restrict access to front-end for updates, which allows attacker to fill the error log"}], "platforms": {"languages": ["Not Language-Specific"]}}, "78": {"name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Non-Repudiation"], "impact": ["Execute Unauthorized Code or Commands", "DoS: Crash, Exit, or Restart", "Read Files or Directories", "Modify Files or Directories", "Read Application Data", "Modify Application Data", "Hide Activities"]}], "mitigations": [{"description": "If at all possible, use library calls rather than external processes to recreate the desired functionality.", "phase": ["Architecture and Design"]}, {"description": "For any data that will be used to generate a command to be executed, keep as much of that data out of external control as possible. For example, in web applications, this may require storing the data locally in the session's state instead of sending it out to the client in a hidden form field.", "phase": ["Architecture and Design"]}, {"description": "For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-s...", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis"}, {"method": "Automated Dynamic Analysis", "description": "This weakness can be detected using dynamic tools and techniques that interact with the product using large test suites with many diverse inputs, such as fuzz testing (fuzzing), robustness testing, an..."}, {"method": "Manual Static Analysis", "description": "Since this weakness does not typically appear frequently within a single software package, manual white box techniques may be able to provide sufficient code coverage and reduction of false positives ..."}], "observed_examples": [{"cve": "CVE-2024-53899", "description": "Virtual environment builder does not correctly quote \"magic\" template strings, allowing OS command injection using a directory whose name contains she..."}, {"cve": "CVE-2025-44844", "description": "file upload functionality in wireless access point allows OS command injection via shell metacharacters through the file name in a Content-Disposition..."}, {"cve": "CVE-2024-6091", "description": "Chain: AI agent platform does not restrict pathnames containing internal \"/./\" sequences (CWE-55), leading to an incomplete denylist (CWE-184) that do..."}, {"cve": "CVE-2024-41316", "description": "Lua application in network device allows OS command injection into os.execute()"}, {"cve": "CVE-2024-44335", "description": "Chain: filter only checks for some shell-injection characters (CWE-184), enabling OS command injection (CWE-78)"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "AI/ML", "Web Server"]}}, "780": {"name": "Use of RSA Algorithm without OAEP", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses the RSA algorithm but does not incorporate Optimal Asymmetric Encryption Padding (OAEP), which might weaken the encryption.", "extended_description": "Padding schemes are often used with cryptographic algorithms to make the plaintext less predictable and complicate attack efforts. The OAEP scheme is often used with RSA to nullify the impact of predictable common text.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "781": {"name": "Improper Address Validation in IOCTL with METHOD_NEITHER I/O Control Code", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product defines an IOCTL that uses METHOD_NEITHER for I/O, but it does not validate or incorrectly validates the addresses that are provided.", "extended_description": "When an IOCTL uses the METHOD_NEITHER option for I/O control, it is the responsibility of the IOCTL to validate the addresses that have been supplied to it. If validation is missing or incorrect, attackers can supply arbitrary memory addresses, leading to code execution or a denial of service.", "consequences": [{"scope": ["Integrity", "Availability", "Confidentiality"], "impact": ["Modify Memory", "Read Memory", "Execute Unauthorized Code or Commands", "DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "If METHOD_NEITHER is required for the IOCTL, then ensure that all user-space addresses are properly validated before they are first accessed. The ProbeForRead and ProbeForWrite routines are available for this task. Also properly protect and manage the user-supplied buffers, since the I/O Manager doe...", "phase": ["Implementation"]}, {"description": "If possible, avoid using METHOD_NEITHER in the IOCTL and select methods that effectively control the buffer size, such as METHOD_BUFFERED, METHOD_IN_DIRECT, or METHOD_OUT_DIRECT.", "phase": ["Architecture and Design"]}, {"description": "If the IOCTL is part of a driver that is only intended to be accessed by trusted users, then use proper access control for the associated device or device namespace. See References.", "phase": ["Architecture and Design", "Implementation"]}], "observed_examples": [{"cve": "CVE-2006-2373", "description": "Driver for file-sharing and messaging protocol allows attackers to execute arbitrary code."}, {"cve": "CVE-2009-0686", "description": "Anti-virus product does not validate addresses, allowing attackers to gain SYSTEM privileges."}, {"cve": "CVE-2009-0824", "description": "DVD software allows attackers to cause a crash."}, {"cve": "CVE-2008-5724", "description": "Personal firewall allows attackers to gain SYSTEM privileges."}, {"cve": "CVE-2007-5756", "description": "chain: device driver for packet-capturing software allows access to an unintended IOCTL with resultant array index error."}], "platforms": {"languages": ["C", "C++"]}}, "782": {"name": "Exposed IOCTL with Insufficient Access Control", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.", "consequences": [{"scope": ["Integrity", "Availability", "Confidentiality"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "In Windows environments, use proper access control for the associated device or device namespace. See References.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2009-2208", "description": "Operating system does not enforce permissions on an IOCTL that can be used to modify network settings."}, {"cve": "CVE-2008-3831", "description": "Device driver does not restrict ioctl calls to its direct rendering manager."}, {"cve": "CVE-2008-3525", "description": "ioctl does not check for a required capability before processing certain requests."}, {"cve": "CVE-2008-0322", "description": "Chain: insecure device permissions allows access to an IOCTL, allowing arbitrary memory to be overwritten."}, {"cve": "CVE-2007-4277", "description": "Chain: anti-virus product uses weak permissions for a device, leading to resultant buffer overflow in an exposed IOCTL."}], "platforms": {"languages": ["C", "C++"]}}, "783": {"name": "Operator Precedence Logic Error", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses an expression in which operator precedence causes incorrect logic to be used.", "extended_description": "While often just a bug, operator precedence logic errors can have serious consequences if they are used in security-critical code, such as making an authentication decision.", "likelihood_of_exploit": "Low", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Varies by Context", "Unexpected State"]}], "mitigations": [{"description": "Regularly wrap sub-expressions in parentheses, especially in security-critical code.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2008-2516", "description": "Authentication module allows authentication bypass because it uses \"(x = call(args) == SUCCESS)\" instead of \"((x = call(args)) == SUCCESS)\"."}, {"cve": "CVE-2008-0599", "description": "Chain: Language interpreter calculates wrong buffer size (CWE-131) by using \"size = ptr ? X : Y\" instead of \"size = (ptr ? X : Y)\" expression."}, {"cve": "CVE-2001-1155", "description": "Chain: product does not properly check the result of a reverse DNS lookup because of operator precedence (CWE-783), allowing bypass of DNS-based acces..."}], "platforms": {"languages": ["C", "C++", "Not Language-Specific"]}}, "784": {"name": "Reliance on Cookies without Validation and Integrity Checking in a Security Decision", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a protection mechanism that relies on the existence or values of a cookie, but it does not properly ensure that the cookie is valid for the associated user.", "extended_description": "Attackers can easily modify cookies, within the browser or by implementing the client-side code outside of the browser. Attackers can bypass protection mechanisms such as authorization and authentication by modifying the cookie to contain an expected value.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Avoid using cookie data for a security-related decision.", "phase": ["Architecture and Design"]}, {"description": "Perform thorough input validation (i.e.: server side validation) on the cookie data if you're going to use it for a security related decision.", "phase": ["Implementation"]}, {"description": "Add integrity checks to detect tampering.", "phase": ["Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2009-1549", "description": "Attacker can bypass authentication by setting a cookie to a specific value."}, {"cve": "CVE-2009-1619", "description": "Attacker can bypass authentication and gain admin privileges by setting an \"admin\" cookie to 1."}, {"cve": "CVE-2009-0864", "description": "Content management system allows admin privileges by setting a \"login\" cookie to \"OK.\""}, {"cve": "CVE-2008-5784", "description": "e-dating application allows admin privileges by setting the admin cookie to 1."}, {"cve": "CVE-2008-6291", "description": "Web-based email list manager allows attackers to gain admin privileges by setting a login cookie to \"admin.\""}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "785": {"name": "Use of Path Manipulation Function without Maximum-sized Buffer", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product invokes a function for normalizing paths or file names, but it provides an output buffer that is smaller than the maximum possible size, such as PATH_MAX.", "extended_description": "Passing an inadequately-sized output buffer to a path manipulation function can result in a buffer overflow. Such functions include realpath(), readlink(), PathAppend(), and others.", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Modify Memory", "Execute Unauthorized Code or Commands", "DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Always specify output buffers large enough to handle the maximum-size possible result from path manipulation functions.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C", "C++"]}}, "786": {"name": "Access of Memory Location Before Start of Buffer", "abstraction": "Base", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product reads or writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.", "extended_description": "This typically occurs when a pointer or its index is decremented to a position before the buffer, when pointer arithmetic results in a position before the beginning of the valid memory location, or when a negative index is used.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}, {"scope": ["Integrity", "Availability"], "impact": ["Modify Memory", "DoS: Crash, Exit, or Restart"]}, {"scope": ["Integrity"], "impact": ["Modify Memory", "Execute Unauthorized Code or Commands"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2002-2227", "description": "Unchecked length of SSLv2 challenge value leads to buffer underflow."}, {"cve": "CVE-2007-4580", "description": "Buffer underflow from a small size value with a large buffer (length parameter inconsistency, CWE-130)"}, {"cve": "CVE-2007-1584", "description": "Buffer underflow from an all-whitespace string, which causes a counter to be decremented before the buffer while looking for a non-whitespace characte..."}, {"cve": "CVE-2007-0886", "description": "Buffer underflow resultant from encoded data that triggers an integer overflow."}, {"cve": "CVE-2006-6171", "description": "Product sets an incorrect buffer size limit, leading to \"off-by-two\" buffer underflow."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "787": {"name": "Out-of-bounds Write", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product writes data past the end, or before the beginning, of the intended buffer.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Memory", "Execute Unauthorized Code or Commands"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Other"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Replace unbounded copy functions with analogous functions that support length arguments, such as strcpy with strncpy. Create these if they are not available.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis"}, {"method": "Automated Dynamic Analysis", "description": "This weakness can be detected using dynamic tools and techniques that interact with the software using large test suites with many diverse inputs, such as fuzz testing (fuzzing), robustness testing, a..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t      compilation to insert runtime error-checking mechanisms\n\t      related to memory safety errors, such as AddressSanitizer\n\t      (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2025-27363", "description": "Font rendering library does not properly\n               handle assigning a signed short value to an unsigned\n               long (CWE-195), leading to..."}, {"cve": "CVE-2023-1017", "description": "The reference implementation code for a Trusted Platform Module does not implement length checks on data, allowing for an attacker to write 2 bytes pa..."}, {"cve": "CVE-2021-21220", "description": "Chain: insufficient input validation (CWE-20) in browser allows heap corruption (CWE-787), as exploited in the wild per CISA KEV."}, {"cve": "CVE-2021-28664", "description": "GPU kernel driver allows memory corruption because a user can obtain read/write access to read-only pages, as exploited in the wild per CISA KEV."}, {"cve": "CVE-2020-17087", "description": "Chain: integer truncation (CWE-197) causes small buffer allocation (CWE-131) leading to out-of-bounds write (CWE-787) in kernel pool, as exploited in ..."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++", "Assembly"], "technologies": ["ICS/OT"]}}, "788": {"name": "Access of Memory Location After End of Buffer", "abstraction": "Base", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product reads or writes to a buffer using an index or pointer that references a memory location after the end of the buffer.", "extended_description": "This typically occurs when a pointer or its index is incremented to a position after the buffer; or when pointer arithmetic results in a position after the buffer.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}, {"scope": ["Integrity", "Availability"], "impact": ["Modify Memory", "DoS: Crash, Exit, or Restart"]}, {"scope": ["Integrity"], "impact": ["Modify Memory", "Execute Unauthorized Code or Commands"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2009-2550", "description": "Classic stack-based buffer overflow in media player using a long entry in a playlist"}, {"cve": "CVE-2009-2403", "description": "Heap-based buffer overflow in media player using a long entry in a playlist"}, {"cve": "CVE-2009-0689", "description": "large precision value in a format string triggers overflow"}, {"cve": "CVE-2009-0558", "description": "attacker-controlled array index leads to code execution"}, {"cve": "CVE-2008-4113", "description": "OS kernel trusts userland-supplied length value, allowing reading of sensitive information"}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "789": {"name": "Memory Allocation with Excessive Size Value", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (Memory)"]}], "mitigations": [{"description": "Perform adequate input validation against any value that influences the amount of memory that is allocated. Define an appropriate strategy for handling requests that exceed the limit, and consider supporting a configuration option so that the administrator can extend the amount of memory to be used ...", "phase": ["Implementation", "Architecture and Design"]}, {"description": "Run your program using system-provided resource limits for memory. This might still cause the program to crash or exit, but the impact to the rest of the system will be minimized.", "phase": ["Operation"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}, {"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2019-19911", "description": "Chain: Python library does not limit the resources used to process images that specify a very large number of bands (CWE-1284), leading to excessive m..."}, {"cve": "CVE-2010-3701", "description": "program uses ::alloca() for encoding messages, but large messages trigger segfault"}, {"cve": "CVE-2008-1708", "description": "memory consumption and daemon exit by specifying a large value in a length field"}, {"cve": "CVE-2008-0977", "description": "large value in a length field leads to memory consumption and crash when no more memory is available"}, {"cve": "CVE-2006-3791", "description": "large key size in game program triggers crash when a resizing function cannot allocate enough memory"}], "platforms": {"languages": ["C", "C++", "Not Language-Specific"]}}, "79": {"name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control", "Confidentiality"], "impact": ["Bypass Protection Mechanism", "Read Application Data"]}, {"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Execute Unauthorized Code or Commands", "Bypass Protection Mechanism", "Read Application Data"]}], "mitigations": [{"description": "Understand all the potential areas where untrusted inputs can enter your software: parameters or arguments, cookies, anything read from the network, environment variables, reverse DNS lookups, query results, request headers, URL components, e-mail, files, filenames, databases, and any external syste...", "phase": ["Architecture and Design", "Implementation"]}, {"description": "For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-s...", "phase": ["Architecture and Design"]}, {"description": "If available, use structured mechanisms that automatically enforce the separation between data and code. These mechanisms may be able to provide the relevant quoting, encoding, and validation automatically, instead of relying on the developer to provide this capability at every point where output is...", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Use automated static analysis tools that target this type of weakness. Many modern techniques use data flow analysis to minimize the number of false positives. This is not a perfect solution, since 10..."}, {"method": "Black Box", "description": "Use the XSS Cheat Sheet [REF-714] or automated test-generation tools to help launch a wide variety of attacks against your web application. The Cheat Sheet contains many subtle XSS variations that are..."}], "observed_examples": [{"cve": "CVE-2024-49038", "description": "XSS in AI assistant"}, {"cve": "CVE-2024-54142", "description": "Plugin that enables AI features allows input with html entities, leading to XSS"}, {"cve": "CVE-2021-25926", "description": "Python Library Manager did not sufficiently neutralize a user-supplied search term, allowing reflected XSS."}, {"cve": "CVE-2021-25963", "description": "Python-based e-commerce platform did not escape returned content on error pages, allowing for reflected Cross-Site Scripting attacks."}, {"cve": "CVE-2021-1879", "description": "Universal XSS in mobile operating system, as exploited in the wild per CISA KEV."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["AI/ML", "Web Based", "Web Server"]}}, "790": {"name": "Improper Filtering of Special Elements", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product receives data from an upstream component, but does not filter or incorrectly filters special elements before sending it to a downstream component.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "791": {"name": "Incomplete Filtering of Special Elements", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives data from an upstream component, but does not completely filter special elements before sending it to a downstream component.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "792": {"name": "Incomplete Filtering of One or More Instances of Special Elements", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives data from an upstream component, but does not completely filter one or more instances of special elements before sending it to a downstream component.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "793": {"name": "Only Filtering One Instance of a Special Element", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives data from an upstream component, but only filters a single instance of a special element before sending it to a downstream component.", "extended_description": "Incomplete filtering of this nature may be location-dependent, as in only the first or last element is filtered.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "794": {"name": "Incomplete Filtering of Multiple Instances of Special Elements", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives data from an upstream component, but does not filter all instances of a special element before sending it to a downstream component.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "795": {"name": "Only Filtering Special Elements at a Specified Location", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives data from an upstream component, but only accounts for special elements at a specified location, thereby missing remaining special elements that may exist before sending it to a downstream component.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "796": {"name": "Only Filtering Special Elements Relative to a Marker", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives data from an upstream component, but only accounts for special elements positioned relative to a marker (e.g. \"at the beginning/end of a string; the second argument\"), thereby missing remaining special elements that may exist before sending it to a downstream component.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "797": {"name": "Only Filtering Special Elements at an Absolute Position", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives data from an upstream component, but only accounts for special elements at an absolute position (e.g. \"byte number 10\"), thereby missing remaining special elements that may exist before sending it to a downstream component.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "798": {"name": "Use of Hard-coded Credentials", "abstraction": "Base", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product contains hard-coded credentials, such as a password or cryptographic key.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Integrity", "Confidentiality", "Availability", "Access Control", "Other"], "impact": ["Read Application Data", "Gain Privileges or Assume Identity", "Execute Unauthorized Code or Commands", "Other"]}], "mitigations": [{"description": "For inbound authentication: Rather than hard-code a default username and password, key, or other authentication credentials for first time logins, utilize a \"first login\" mode that requires the user to enter a unique strong password or key.", "phase": ["Architecture and Design"]}, {"description": "If the product must contain hard-coded credentials or they cannot be removed, perform access control checks and limit which entities can access the feature that requires the hard-coded credentials. For example, a feature might only be enabled through the system console instead of through a network c...", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Black Box", "description": "Credential storage in configuration files is findable using black box methods, but the use of hard-coded credentials for an incoming authentication routine typically involves an account that is not vi..."}, {"method": "Automated Static Analysis", "description": "Automated white box techniques have been published for detecting hard-coded credentials for incoming authentication, but there is some expert disagreement regarding their effectiveness and applicabili..."}, {"method": "Manual Static Analysis", "description": "This weakness may be detectable using manual code analysis. Unless authentication is decentralized and applied throughout the product, there can be sufficient time for the analyst to find incoming aut..."}], "observed_examples": [{"cve": "CVE-2022-40263", "description": "Software for biological cell analysus has hard-coded credentials, leading to leak of Protected Health Information (PHI)"}, {"cve": "CVE-2022-29953", "description": "Condition Monitor firmware has a maintenance interface with hard-coded credentials"}, {"cve": "CVE-2022-29960", "description": "Engineering Workstation uses hard-coded cryptographic keys that could allow for unathorized filesystem access and privilege escalation"}, {"cve": "CVE-2022-29964", "description": "Distributed Control System (DCS) has hard-coded passwords for local shell access"}, {"cve": "CVE-2022-30997", "description": "Programmable Logic Controller (PLC) has a maintenance service that uses undocumented, hard-coded credentials"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Mobile", "ICS/OT"]}}, "799": {"name": "Improper Control of Interaction Frequency", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests.", "extended_description": "This can allow the actor to perform actions more frequently than expected. The actor could be a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic (such as limiting humans to a single vote), or other consequences. For example, an authentication routine might not limit the number of times an attacker can guess a password. Or, a web site might conduct a poll but only expect humans to vote a maximum of once a day.", "consequences": [{"scope": ["Availability", "Access Control", "Other"], "impact": ["DoS: Resource Consumption (Other)", "Bypass Protection Mechanism", "Other"]}], "observed_examples": [{"cve": "CVE-2024-50653", "description": "Chain: e-commerce product has a \"front-end restriction\" for coupon use (CWE-602), but the server does not restrict the number of requests for the same..."}, {"cve": "CVE-2002-1876", "description": "Mail server allows attackers to prevent other users from accessing mail by sending large number of rapid requests."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based", "Web Server"]}}, "8": {"name": "J2EE Misconfiguration: Entity Bean Declared Remote", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "When an application exposes a remote interface for an entity bean, it might also expose methods that get or set the bean's data. These methods could be leveraged to read sensitive information, or to change data in ways that violate the application's expectations, potentially leading to other vulnerabilities.", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data"]}], "mitigations": [{"description": "Declare Java beans \"local\" when possible. When a bean must be remotely accessible, make sure that sensitive information is not exposed, and ensure that the application logic performs appropriate validation of any data that might be modified by an attacker.", "phase": ["Implementation"]}], "platforms": {"languages": ["Java"]}}, "80": {"name": "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\", and \"&\" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Read Application Data", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Carefully check each input parameter against a rigorous positive specification (allowlist) defining the specific characters and format allowed. All input should be neutralized, not just parameters that the user is supposed to specify, but all data in the request, including hidden fields, cookies, he...", "phase": ["Implementation"]}, {"description": "With Struts, write all data from form beans with the bean's filter attribute set to true.", "phase": ["Implementation"]}, {"description": "To help mitigate XSS attacks against the user's session cookie, set the session cookie to be HttpOnly. In browsers that support the HttpOnly feature (such as more recent versions of Internet Explorer and Firefox), this attribute can prevent the user's session cookie from being accessible to maliciou...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2002-0938", "description": "XSS in parameter in a link."}, {"cve": "CVE-2002-1495", "description": "XSS in web-based email product via attachment filenames."}, {"cve": "CVE-2003-1136", "description": "HTML injection in posted message."}, {"cve": "CVE-2004-2171", "description": "XSS not quoted in error page."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "804": {"name": "Guessable CAPTCHA", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a CAPTCHA challenge, but the challenge can be guessed or automatically recognized by a non-human actor.", "consequences": [{"scope": ["Access Control", "Other"], "impact": ["Bypass Protection Mechanism", "Other"]}], "observed_examples": [{"cve": "CVE-2022-4036", "description": "Chain: appointment booking app uses a weak hash (CWE-328) for generating a CAPTCHA, making it guessable  (CWE-804)"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Server"]}}, "805": {"name": "Buffer Access with Incorrect Length Value", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a sequential operation to read or write a buffer, but it uses an incorrect length value that causes it to access memory that is outside of the bounds of the buffer.", "extended_description": "When the length value exceeds the size of the destination, a buffer overflow could occur.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Read Memory", "Modify Memory", "Execute Unauthorized Code or Commands"]}, {"scope": ["Availability"], "impact": ["Modify Memory", "DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)"]}], "mitigations": [{"description": "For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-s...", "phase": ["Architecture and Design"]}, {"description": "Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the p...", "phase": ["Architecture and Design", "Operation"]}], "detection_methods": [{"method": "Automated Static Analysis"}, {"method": "Automated Dynamic Analysis", "description": "This weakness can be detected using dynamic tools and techniques that interact with the product using large test suites with many diverse inputs, such as fuzz testing (fuzzing), robustness testing, an..."}, {"method": "Manual Analysis", "description": "Manual analysis can be useful for finding this weakness, but it might not achieve desired code coverage within limited time constraints. This becomes difficult for weaknesses that must be considered f..."}], "observed_examples": [{"cve": "CVE-2011-1959", "description": "Chain: large length value causes buffer over-read (CWE-126)"}, {"cve": "CVE-2011-1848", "description": "Use of packet length field to make a calculation, then copy into a fixed-size buffer"}, {"cve": "CVE-2011-0105", "description": "Chain: retrieval of length value from an uninitialized memory location"}, {"cve": "CVE-2011-0606", "description": "Crafted length value in document reader leads to buffer overflow"}, {"cve": "CVE-2011-0651", "description": "SSL server overflow when the sum of multiple length fields exceeds a given value"}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++", "Assembly"]}}, "806": {"name": "Buffer Access Using Size of Source Buffer", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses the size of a source buffer when reading from or writing to a destination buffer, which may cause it to access memory that is outside of the bounds of the buffer.", "extended_description": "When the size of the destination is smaller than the size of the source, a buffer overflow could occur.", "consequences": [{"scope": ["Availability"], "impact": ["Modify Memory", "DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)"]}, {"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Read Memory", "Modify Memory", "Execute Unauthorized Code or Commands"]}, {"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "mitigations": [{"description": "Use an abstraction library to abstract away risky APIs. Examples include the Safe C String Library (SafeStr) by Viega, and the Strsafe.h library from Microsoft. This is not a complete solution, since many buffer overflows are not related to strings.", "phase": ["Architecture and Design"]}, {"description": "Programmers should adhere to the following rules when allocating and managing their applications memory: Double check that your buffer is as large as you specify. When using functions that accept a number of bytes to copy, such as strncpy(), be aware that if the destination buffer size is equal to t...", "phase": ["Implementation"]}, {"description": "Most mitigating technologies at the compiler or OS level to date address only a subset of buffer overflow problems and rarely provide complete protection against even that subset. It is good practice to implement strategies to increase the workload of an attacker, such as leaving the attacker to gue...", "phase": ["Build and Compilation", "Operation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "807": {"name": "Reliance on Untrusted Inputs in a Security Decision", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality", "Access Control", "Availability", "Other"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity", "Varies by Context"]}], "mitigations": [{"description": "For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-s...", "phase": ["Architecture and Design"]}, {"description": "When using PHP, configure the application so that it does not use register_globals. During implementation, develop the application so that it does not rely on this feature, but be wary of implementing a register_globals emulation that is subject to weaknesses such as CWE-95, CWE-621, and similar iss...", "phase": ["Operation", "Implementation"]}], "detection_methods": [{"method": "Manual Static Analysis", "description": "Since this weakness does not typically appear frequently within a single software package, manual white box techniques may be able to provide sufficient code coverage and reduction of false positives ..."}, {"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Manual Static Analysis - Binary or Bytecode"}], "observed_examples": [{"cve": "CVE-2009-1549", "description": "Attacker can bypass authentication by setting a cookie to a specific value."}, {"cve": "CVE-2009-1619", "description": "Attacker can bypass authentication and gain admin privileges by setting an \"admin\" cookie to 1."}, {"cve": "CVE-2009-0864", "description": "Content management system allows admin privileges by setting a \"login\" cookie to \"OK.\""}, {"cve": "CVE-2008-5784", "description": "e-dating application allows admin privileges by setting the admin cookie to 1."}, {"cve": "CVE-2008-6291", "description": "Web-based email list manager allows attackers to gain admin privileges by setting a login cookie to \"admin.\""}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based", "Web Server"]}}, "81": {"name": "Improper Neutralization of Script in an Error Message Web Page", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters that could be interpreted as web-scripting elements when they are sent to an error page.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Read Application Data", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Do not write user-controlled input to error pages.", "phase": ["Implementation"]}, {"description": "Carefully check each input parameter against a rigorous positive specification (allowlist) defining the specific characters and format allowed. All input should be neutralized, not just parameters that the user is supposed to specify, but all data in the request, including hidden fields, cookies, he...", "phase": ["Implementation"]}, {"description": "With Struts, write all data from form beans with the bean's filter attribute set to true.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2002-0840", "description": "XSS in default error page from Host: header."}, {"cve": "CVE-2002-1053", "description": "XSS in error message."}, {"cve": "CVE-2002-1700", "description": "XSS in error page from targeted parameter."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "82": {"name": "Improper Neutralization of Script in Attributes of IMG Tags in a Web Page", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The web application does not neutralize or incorrectly neutralizes scripting elements within attributes of HTML IMG tags, such as the src attribute.", "extended_description": "Attackers can embed XSS exploits into the values for IMG attributes (e.g. SRC) that is streamed and then executed in a victim's browser. Note that when the page is loaded into a user's browsers, the exploit will automatically execute.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Read Application Data", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "To help mitigate XSS attacks against the user's session cookie, set the session cookie to be HttpOnly. In browsers that support the HttpOnly feature (such as more recent versions of Internet Explorer and Firefox), this attribute can prevent the user's session cookie from being accessible to maliciou...", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2006-3211", "description": "Stored XSS in a guestbook application using a javascript: URI in a bbcode img tag."}, {"cve": "CVE-2002-1649", "description": "javascript URI scheme in IMG tag."}, {"cve": "CVE-2002-1803", "description": "javascript URI scheme in IMG tag."}, {"cve": "CVE-2002-1804", "description": "javascript URI scheme in IMG tag."}, {"cve": "CVE-2002-1805", "description": "javascript URI scheme in IMG tag."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "820": {"name": "Missing Synchronization", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product utilizes a shared resource in a concurrent manner but does not attempt to synchronize access to the resource.", "extended_description": "If access to a shared resource is not synchronized, then the resource may not be in a state that is expected by the product. This might lead to unexpected or insecure behaviors, especially if an attacker can influence the shared resource.", "consequences": [{"scope": ["Integrity", "Confidentiality", "Other"], "impact": ["Modify Application Data", "Read Application Data", "Alter Execution Logic"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "821": {"name": "Incorrect Synchronization", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product utilizes a shared resource in a concurrent manner, but it does not correctly synchronize access to the resource.", "extended_description": "If access to a shared resource is not correctly synchronized, then the resource may not be in a state that is expected by the product. This might lead to unexpected or insecure behaviors, especially if an attacker can influence the shared resource.", "consequences": [{"scope": ["Integrity", "Confidentiality", "Other"], "impact": ["Modify Application Data", "Read Application Data", "Alter Execution Logic"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "822": {"name": "Untrusted Pointer Dereference", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands", "Modify Memory"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2007-5655", "description": "message-passing framework interprets values in packets as pointers, causing a crash."}, {"cve": "CVE-2010-2299", "description": "labeled as a \"type confusion\" issue, also referred to as a \"stale pointer.\" However, the bug ID says \"contents are simply interpreted as a pointer... ..."}, {"cve": "CVE-2009-1719", "description": "Untrusted dereference using undocumented constructor."}, {"cve": "CVE-2009-1250", "description": "An error code is incorrectly checked and interpreted as a pointer, leading to a crash."}, {"cve": "CVE-2009-0311", "description": "An untrusted value is obtained from a packet and directly called as a function pointer, leading to code execution."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "823": {"name": "Use of Out-of-range Pointer Offset", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands", "Modify Memory"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2010-2160", "description": "Invalid offset in undocumented opcode leads to memory corruption."}, {"cve": "CVE-2010-1281", "description": "Multimedia player uses untrusted value from a file when using file-pointer calculations."}, {"cve": "CVE-2009-3129", "description": "Spreadsheet program processes a record with an invalid size field, which is later used as an offset."}, {"cve": "CVE-2009-2694", "description": "Instant messaging library does not validate an offset value specified in a packet."}, {"cve": "CVE-2009-2687", "description": "Language interpreter does not properly handle invalid offsets in JPEG image, leading to out-of-bounds memory access and crash."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "824": {"name": "Access of Uninitialized Pointer", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product accesses or uses a pointer that has not been initialized.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t      compilation to insert runtime error-checking mechanisms\n\t      related to memory safety errors, such as AddressSanitizer\n\t      (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2024-32878", "description": "LLM product has a free of an uninitialized pointer"}, {"cve": "CVE-2019-3836", "description": "Chain: secure communications library does not initialize a local variable for a data structure (CWE-456), leading to access of an uninitialized pointe..."}, {"cve": "CVE-2018-14641", "description": "Chain: C union member is not initialized (CWE-456), leading to access of invalid pointer (CWE-824)"}, {"cve": "CVE-2010-0211", "description": "chain: unchecked return value (CWE-252) leads to free of invalid, uninitialized pointer (CWE-824)."}, {"cve": "CVE-2009-2768", "description": "Pointer in structure is not initialized, leading to NULL pointer dereference (CWE-476) and system crash."}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "825": {"name": "Expired Pointer Dereference", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.", "extended_description": "When a product releases memory, but it maintains a pointer to that memory, then the memory might be re-allocated at a later time. If the original pointer is accessed to read or write data, then this could cause the product to read or modify data that is in use by a different function or process. Depending on how the newly-allocated memory is used, this could lead to a denial of service, information exposure, or code execution.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Choose a language that provides automatic memory management.", "phase": ["Architecture and Design"]}, {"description": "When freeing pointers, be sure to set them to NULL once they are freed. However, the utilization of multiple or complex data structures may lower the usefulness of this strategy.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}, {"method": "Automated Dynamic Analysis", "description": "Use tools that are integrated during\n\t     compilation to insert runtime error-checking mechanisms\n\t     related to memory safety errors, such as AddressSanitizer\n\t     (ASan) for C/C++ [REF-1518]."}], "observed_examples": [{"cve": "CVE-2023-26463", "description": "Chain: IPSec VPN product uses the same variable for multiple purposes in the same function (CWE-1109), leading to incorrect access control (CWE-284) a..."}, {"cve": "CVE-2008-5013", "description": "access of expired memory address leads to arbitrary code execution"}, {"cve": "CVE-2010-3257", "description": "stale pointer issue leads to denial of service and possibly other consequences"}, {"cve": "CVE-2008-0062", "description": "Chain: a message having an unknown message type may cause a reference to uninitialized memory resulting in a null pointer dereference (CWE-476) or dan..."}, {"cve": "CVE-2007-1211", "description": "read of value at an offset into a structure after the offset is no longer valid"}], "platforms": {"languages": ["Memory-Unsafe", "C", "C++"]}}, "826": {"name": "Premature Release of Resource During Expected Lifetime", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product releases a resource that is still intended to be used by itself or another actor.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data", "Read Memory"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}, {"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands", "Modify Application Data", "Modify Memory"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2009-3547", "description": "Chain: race condition (CWE-362) might allow resource to be released before operating on it, leading to NULL dereference (CWE-476)"}], "platforms": {"languages": ["Not Language-Specific"]}}, "827": {"name": "Improper Control of Document Type Definition", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not restrict a reference to a Document Type Definition (DTD) to the intended control sphere. This might allow attackers to reference arbitrary DTDs, possibly causing the product to expose files, consume excessive system resources, or execute arbitrary http requests on behalf of the attacker.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Files or Directories"]}, {"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)"]}, {"scope": ["Integrity", "Confidentiality", "Availability", "Access Control"], "impact": ["Execute Unauthorized Code or Commands", "Gain Privileges or Assume Identity"]}], "observed_examples": [{"cve": "CVE-2010-2076", "description": "Product does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers,..."}], "platforms": {"languages": ["XML"]}}, "828": {"name": "Signal Handler with Functionality that is not Asynchronous-Safe", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product defines a signal handler that contains code sequences that are not asynchronous-safe, i.e., the functionality is not reentrant, or it can be interrupted.", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["DoS: Crash, Exit, or Restart", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Where non-reentrant functionality must be leveraged within a signal handler, be sure to block or mask signals appropriately. This includes blocking other signals within the signal handler itself that may also leverage the functionality. It also includes blocking all signals reliant upon the function...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2008-4109", "description": "Signal handler uses functions that ultimately call the unsafe syslog/malloc/s*printf, leading to denial of service via multiple login attempts"}, {"cve": "CVE-2006-5051", "description": "Chain: Signal handler contains too much functionality (CWE-828), introducing a race condition (CWE-362) that leads to a double free (CWE-415)."}, {"cve": "CVE-2001-1349", "description": "unsafe calls to library functions from signal handler"}, {"cve": "CVE-2004-0794", "description": "SIGURG can be used to remotely interrupt signal handler; other variants exist."}, {"cve": "CVE-2004-2259", "description": "SIGCHLD signal to FTP server can cause crash under heavy load while executing non-reentrant functions like malloc/free."}], "platforms": {"languages": ["Not Language-Specific", "C"]}}, "829": {"name": "Inclusion of Functionality from Untrusted Control Sphere", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482].", "phase": ["Architecture and Design"]}, {"description": "For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-s...", "phase": ["Architecture and Design"]}, {"description": "Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the s...", "phase": ["Architecture and Design", "Operation"]}], "detection_methods": [{"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Manual Static Analysis - Binary or Bytecode"}, {"method": "Dynamic Analysis with Manual Results Interpretation"}], "observed_examples": [{"cve": "CVE-2010-2076", "description": "Product does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers,..."}, {"cve": "CVE-2004-0285", "description": "Modification of assumed-immutable configuration variable in include file allows file inclusion via direct request."}, {"cve": "CVE-2004-0030", "description": "Modification of assumed-immutable configuration variable in include file allows file inclusion via direct request."}, {"cve": "CVE-2004-0068", "description": "Modification of assumed-immutable configuration variable in include file allows file inclusion via direct request."}, {"cve": "CVE-2005-2157", "description": "Modification of assumed-immutable configuration variable in include file allows file inclusion via direct request."}], "platforms": {"languages": ["Not Language-Specific"]}}, "83": {"name": "Improper Neutralization of Script in Attributes in a Web Page", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not neutralize or incorrectly neutralizes \"javascript:\" or other URIs from dangerous attributes within tags, such as onmouseover, onload, onerror, or style.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Read Application Data", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Carefully check each input parameter against a rigorous positive specification (allowlist) defining the specific characters and format allowed. All input should be neutralized, not just parameters that the user is supposed to specify, but all data in the request, including tag attributes, hidden fie...", "phase": ["Implementation"]}, {"description": "With Struts, write all data from form beans with the bean's filter attribute set to true.", "phase": ["Implementation"]}, {"description": "To help mitigate XSS attacks against the user's session cookie, set the session cookie to be HttpOnly. In browsers that support the HttpOnly feature (such as more recent versions of Internet Explorer and Firefox), this attribute can prevent the user's session cookie from being accessible to maliciou...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2001-0520", "description": "Bypass filtering of SCRIPT tags using onload in BODY, href in A, BUTTON, INPUT, and others."}, {"cve": "CVE-2002-1493", "description": "guestbook XSS in STYLE or IMG SRC attributes."}, {"cve": "CVE-2002-1965", "description": "Javascript in onerror attribute of IMG tag."}, {"cve": "CVE-2002-1495", "description": "XSS in web-based email product via onmouseover event."}, {"cve": "CVE-2002-1681", "description": "XSS via script in <P> tag."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "830": {"name": "Inclusion of Web Functionality from an Untrusted Source", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product includes web functionality (such as a web widget) from another domain, which causes it to operate within the domain of the product, potentially granting total access and control of the product to the untrusted source.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "831": {"name": "Signal Handler Function Associated with Multiple Signals", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product defines a function that is used as a handler for more than one signal.", "consequences": [{"scope": ["Availability", "Integrity", "Confidentiality", "Access Control", "Other"], "impact": ["DoS: Crash, Exit, or Restart", "Execute Unauthorized Code or Commands", "Read Application Data", "Gain Privileges or Assume Identity", "Bypass Protection Mechanism", "Varies by Context"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "832": {"name": "Unlock of a Resource that is not Locked", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product attempts to unlock a resource that is not locked.", "extended_description": "Depending on the locking functionality, an unlock of a non-locked resource might cause memory corruption or other modification to the resource (or its associated metadata that is used for tracking locks).", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability", "Other"], "impact": ["DoS: Crash, Exit, or Restart", "Execute Unauthorized Code or Commands", "Modify Memory", "Other"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2010-4210", "description": "function in OS kernel unlocks a mutex that was not previously locked, causing a panic or overwrite of arbitrary memory."}, {"cve": "CVE-2008-4302", "description": "Chain: OS kernel does not properly handle a failure of a function call (CWE-755), leading to an unlock of a resource that was not locked (CWE-832), wi..."}, {"cve": "CVE-2009-1243", "description": "OS kernel performs an unlock in some incorrect circumstances, leading to panic."}], "platforms": {"languages": ["Not Language-Specific"]}}, "833": {"name": "Deadlock", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains multiple threads or executable segments that are waiting for each other to release a necessary lock, resulting in deadlock.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Other)", "DoS: Crash, Exit, or Restart"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-1999-1476", "description": "A bug in some Intel Pentium processors allow DoS (hang) via an invalid \"CMPXCHG8B\" instruction, causing a deadlock"}, {"cve": "CVE-2009-2857", "description": "OS deadlock"}, {"cve": "CVE-2009-1961", "description": "OS deadlock involving 3 separate functions"}, {"cve": "CVE-2009-2699", "description": "deadlock in library"}, {"cve": "CVE-2009-4272", "description": "deadlock triggered by packets that force collisions in a routing table"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "834": {"name": "Excessive Iteration", "abstraction": "Class", "mapping": "DISCOURAGED", "structure": "Simple", "description": "The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.", "extended_description": "If the iteration can be influenced by an attacker, this weakness could allow attackers to consume excessive resources such as CPU or memory. In many cases, a loop does not need to be infinite in order to cause enough resource consumption to adversely affect the product or its host system; it depends on the amount of resources consumed per iteration.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Amplification", "DoS: Crash, Exit, or Restart"]}], "detection_methods": [{"method": "Dynamic Analysis with Manual Results Interpretation"}, {"method": "Manual Static Analysis - Source Code"}, {"method": "Automated Static Analysis - Source Code"}], "observed_examples": [{"cve": "CVE-2011-1027", "description": "Chain: off-by-one error (CWE-193) leads to infinite loop (CWE-835) using invalid hex-encoded characters."}, {"cve": "CVE-2006-6499", "description": "Chain: web browser crashes due to infinite loop - \"bad\n\t      looping logic [that relies on] floating point math [CWE-1339] to exit\n\t      the loop [C..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "835": {"name": "Loop with Unreachable Exit Condition ('Infinite Loop')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Amplification"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-22224", "description": "Chain: an operating system does not properly process malformed Open Shortest Path First (OSPF) Type/Length/Value Identifiers (TLV) (CWE-703), which ca..."}, {"cve": "CVE-2022-25304", "description": "A Python machine communication platform did not account for receiving a malformed packet with a null size, causing the receiving function to never upd..."}, {"cve": "CVE-2011-1027", "description": "Chain: off-by-one error (CWE-193) leads to infinite loop (CWE-835) using invalid hex-encoded characters."}, {"cve": "CVE-2011-1142", "description": "Chain: self-referential values in recursive definitions lead to infinite loop."}, {"cve": "CVE-2011-1002", "description": "NULL UDP packet is never cleared from a queue, leading to infinite loop."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "836": {"name": "Use of Password Hash Instead of Password for Authentication", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product records password hashes in a data store, receives a hash of a password from a client, and compares the supplied hash to the hash obtained from the data store.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}], "observed_examples": [{"cve": "CVE-2009-1283", "description": "Product performs authentication with user-supplied password hashes that can be obtained from a separate SQL injection vulnerability (CVE-2009-1282)."}, {"cve": "CVE-2005-3435", "description": "Product allows attackers to bypass authentication by obtaining the password hash for another user and specifying the hash in the pwd argument."}], "platforms": {"languages": ["Not Language-Specific"]}}, "837": {"name": "Improper Enforcement of a Single, Unique Action", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product requires that an actor should only be able to perform an action once, or to have only one unique action, but the product does not enforce or improperly enforces this restriction.", "extended_description": "In various applications, a user is only expected to perform a certain action once, such as voting, requesting a refund, or making a purchase. When this restriction is not enforced, sometimes this can have security implications. For example, in a voting application, an attacker could attempt to \"stuff the ballot box\" by voting multiple times. If these votes are counted separately, then the attacker could directly affect who wins the vote. This could have significant business impact depending on t...", "consequences": [{"scope": ["Other"], "impact": ["Varies by Context"]}], "observed_examples": [{"cve": "CVE-2008-0294", "description": "Ticket-booking web application allows a user to lock a seat more than once."}, {"cve": "CVE-2005-4051", "description": "CMS allows people to rate downloads by voting more than once."}, {"cve": "CVE-2002-216", "description": "Polling software allows people to vote more than once by setting a cookie."}, {"cve": "CVE-2003-1433", "description": "Chain: lack of validation of a challenge key in a game allows a player to register multiple times and lock other players out of the game."}, {"cve": "CVE-2002-1018", "description": "Library feature allows attackers to check out the same e-book multiple times, preventing other users from accessing copies of the e-book."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based", "Web Server"]}}, "838": {"name": "Inappropriate Encoding for Output Context", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses or specifies an encoding when generating output to a downstream component, but the specified encoding is not the same as the encoding that is expected by the downstream component.", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Modify Application Data", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Use context-aware encoding. That is, understand which encoding is being used by the downstream component, and ensure that this encoding is used. If an encoding can be specified, do so, instead of assuming that the default encoding is the same as the default being assumed by the downstream component.", "phase": ["Implementation"]}, {"description": "Where possible, use communications protocols or data formats that provide strict boundaries between control and data. If this is not feasible, ensure that the protocols or formats allow the communicating components to explicitly state which encoding/decoding method is being used. Some template frame...", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2009-2814", "description": "Server does not properly handle requests that do not contain UTF-8 data; browser assumes UTF-8, allowing XSS."}], "platforms": {"languages": ["Not Language-Specific"]}}, "839": {"name": "Numeric Range Comparison Without Minimum Check", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product checks a value to ensure that it is less than or equal to a maximum, but it does not also verify that the value is greater than or equal to the minimum.", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Modify Application Data", "Execute Unauthorized Code or Commands"]}, {"scope": ["Availability"], "impact": ["DoS: Resource Consumption (Other)"]}, {"scope": ["Confidentiality", "Integrity"], "impact": ["Modify Memory", "Read Memory"]}], "mitigations": [{"description": "If the number to be used is always expected to be positive, change the variable type from signed to unsigned or size_t.", "phase": ["Implementation"]}, {"description": "If the number to be used could have a negative value based on the specification (thus requiring a signed value), but the number should only be positive to preserve code correctness, then include a check to ensure that the value is positive.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2010-1866", "description": "Chain: integer overflow (CWE-190) causes a negative signed value, which later bypasses a maximum-only check (CWE-839), leading to heap-based buffer ov..."}, {"cve": "CVE-2009-1099", "description": "Chain: 16-bit counter can be interpreted as a negative value, compared to a 32-bit maximum value, leading to buffer under-write."}, {"cve": "CVE-2011-0521", "description": "Chain: kernel's lack of a check for a negative value leads to memory corruption."}, {"cve": "CVE-2010-3704", "description": "Chain: parser uses atoi() but does not check for a negative value, which can happen on some platforms, leading to buffer under-write."}, {"cve": "CVE-2010-2530", "description": "Chain: Negative value stored in an int bypasses a size check and causes allocation of large amounts of memory."}], "platforms": {"languages": ["C", "C++"]}}, "84": {"name": "Improper Neutralization of Encoded URI Schemes in a Web Page", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The web application improperly neutralizes user-controlled input for executable script disguised with URI encodings.", "consequences": [{"scope": ["Integrity"], "impact": ["Unexpected State"]}], "mitigations": [{"description": "Resolve all URIs to absolute or canonical representations before processing.", "phase": ["Implementation"]}, {"description": "Carefully check each input parameter against a rigorous positive specification (allowlist) defining the specific characters and format allowed. All input should be neutralized, not just parameters that the user is supposed to specify, but all data in the request, including tag attributes, hidden fie...", "phase": ["Implementation"]}, {"description": "With Struts, write all data from form beans with the bean's filter attribute set to true.", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2005-0563", "description": "Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbi..."}, {"cve": "CVE-2005-2276", "description": "Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script..."}, {"cve": "CVE-2005-0692", "description": "Encoded script within BBcode IMG tag."}, {"cve": "CVE-2002-0117", "description": "Encoded \"javascript\" in IMG tag."}, {"cve": "CVE-2002-0118", "description": "Encoded \"javascript\" in IMG tag."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "841": {"name": "Improper Enforcement of Behavioral Workflow", "abstraction": "Class", "mapping": "ALLOWED", "structure": "Simple", "description": "The product supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.", "consequences": [{"scope": ["Other"], "impact": ["Alter Execution Logic"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2011-0348", "description": "Bypass of access/billing restrictions by sending traffic to an unrestricted destination before sending to a restricted destination."}, {"cve": "CVE-2007-3012", "description": "Attacker can access portions of a restricted page by canceling out of a dialog."}, {"cve": "CVE-2009-5056", "description": "Ticket-tracking system does not enforce a permission setting."}, {"cve": "CVE-2004-2164", "description": "Shopping cart does not close a database connection when user restores a previous order, leading to connection exhaustion."}, {"cve": "CVE-2003-0777", "description": "Chain: product does not properly handle dropped connections, leading to missing NULL terminator (CWE-170) and segmentation fault."}], "platforms": {"languages": ["Not Language-Specific"]}}, "842": {"name": "Placement of User into Incorrect Group", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product or the administrator places a user into an incorrect group.", "extended_description": "If the incorrect group has more access or privileges than the intended group, the user might be able to bypass intended security policy to access unexpected resources or perform unexpected actions. The access-control system might not be able to detect malicious usage of this group membership.", "consequences": [{"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}], "observed_examples": [{"cve": "CVE-1999-1193", "description": "Operating system assigns user to privileged wheel group, allowing the user to gain root privileges."}, {"cve": "CVE-2010-3716", "description": "Chain: drafted web request allows the creation of users with arbitrary group membership."}, {"cve": "CVE-2008-5397", "description": "Chain: improper processing of configuration options causes users to contain unintended group memberships."}, {"cve": "CVE-2007-6644", "description": "CMS does not prevent remote administrators from promoting other users to the administrator group, in violation of the intended security model."}, {"cve": "CVE-2007-3260", "description": "Product assigns members to the root group, allowing escalation of privileges."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "843": {"name": "Access of Resource Using Incompatible Type ('Type Confusion')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.", "consequences": [{"scope": ["Availability", "Integrity", "Confidentiality"], "impact": ["Read Memory", "Modify Memory", "Execute Unauthorized Code or Commands", "DoS: Crash, Exit, or Restart"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2025-32352", "description": "Type confusion in PHP app allows authentication bypass when users have passwords whose MD5 hashes can be interpreted as numbers"}, {"cve": "CVE-2010-4577", "description": "Type confusion in CSS sequence leads to out-of-bounds read."}, {"cve": "CVE-2011-0611", "description": "Size inconsistency allows code execution, first discovered when it was actively exploited in-the-wild."}, {"cve": "CVE-2010-0258", "description": "Improperly-parsed file containing records of different types leads to code execution when a memory location is interpreted as a different object than ..."}], "platforms": {"languages": ["C", "C++"]}}, "85": {"name": "Doubled Character XSS Manipulations", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The web application does not filter user-controlled input for executable script disguised using doubling of the involved characters.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Read Application Data", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Resolve all filtered input to absolute or canonical representations before processing.", "phase": ["Implementation"]}, {"description": "Carefully check each input parameter against a rigorous positive specification (allowlist) defining the specific characters and format allowed. All input should be neutralized, not just parameters that the user is supposed to specify, but all data in the request, including tag attributes, hidden fie...", "phase": ["Implementation"]}, {"description": "With Struts, write all data from form beans with the bean's filter attribute set to true.", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-2086", "description": "XSS using \"<script\"."}, {"cve": "CVE-2000-0116", "description": "Encoded \"javascript\" in IMG tag."}, {"cve": "CVE-2001-1157", "description": "Extra \"<\" in front of SCRIPT tag."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "86": {"name": "Improper Neutralization of Invalid Characters in Identifiers in Web Pages", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not neutralize or incorrectly neutralizes invalid characters or byte sequences in the middle of tag names, URI schemes, and other identifiers.", "extended_description": "Some web browsers may remove these sequences, resulting in output that may have unintended control implications. For example, the product may attempt to remove a \"javascript:\" URI scheme, but a \"java%00script:\" URI may bypass this check and still be rendered as active javascript by some browsers, allowing XSS or other attacks.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Read Application Data", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "To help mitigate XSS attacks against the user's session cookie, set the session cookie to be HttpOnly. In browsers that support the HttpOnly feature (such as more recent versions of Internet Explorer and Firefox), this attribute can prevent the user's session cookie from being accessible to maliciou...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2004-0595", "description": "XSS filter doesn't filter null characters before looking for dangerous tags, which are ignored by web browsers. Multiple Interpretation Error (MIE) an..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "862": {"name": "Missing Authorization", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not perform an authorization check when an actor attempts to access a resource or perform an action.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data", "Read Files or Directories"]}, {"scope": ["Integrity"], "impact": ["Modify Application Data", "Modify Files or Directories"]}, {"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity", "Bypass Protection Mechanism"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Resource Consumption (Other)"]}], "mitigations": [{"description": "Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for ...", "phase": ["Architecture and Design"]}, {"description": "Use the access control capabilities of your operating system and server environment and define your access control lists accordingly. Use a \"default deny\" policy when defining these ACLs.", "phase": ["System Configuration", "Installation"]}], "detection_methods": [{"method": "Automated Static Analysis"}, {"method": "Automated Dynamic Analysis", "description": "Automated dynamic analysis may find many or all possible interfaces that do not require authorization, but manual analysis is required to determine if the lack of authorization violates business logic..."}, {"method": "Manual Analysis"}], "observed_examples": [{"cve": "CVE-2024-6845", "description": "chatbot Wordpress plugin does not perform authorization on a REST endpoint, allowing retrieval of an API key"}, {"cve": "CVE-2025-2224", "description": "AI-enabled WordPress plugin has a missing capability check for a particular function, allowing changing public status of posts"}, {"cve": "CVE-2022-24730", "description": "Go-based continuous deployment product does not check that a user has certain privileges to update or create an app, allowing adversaries to read sens..."}, {"cve": "CVE-2009-3168", "description": "Web application does not restrict access to admin scripts, allowing authenticated users to reset administrative passwords."}, {"cve": "CVE-2009-3597", "description": "Web application stores database file under the web root with insufficient access control (CWE-219), allowing direct request."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["AI/ML", "Web Server", "Database Server", "Not Technology-Specific"]}}, "863": {"name": "Incorrect Authorization", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data", "Read Files or Directories"]}, {"scope": ["Integrity"], "impact": ["Modify Application Data", "Modify Files or Directories"]}, {"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity", "Bypass Protection Mechanism"]}, {"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart", "DoS: Resource Consumption (CPU)", "DoS: Resource Consumption (Memory)", "DoS: Resource Consumption (Other)"]}], "mitigations": [{"description": "Ensure that access control checks are performed related to the business logic. These checks may be different than the access control checks that are applied to more generic resources such as files, connections, processes, memory, and database records. For example, a database may restrict access for ...", "phase": ["Architecture and Design"]}, {"description": "Use the access control capabilities of your operating system and server environment and define your access control lists accordingly. Use a \"default deny\" policy when defining these ACLs.", "phase": ["System Configuration", "Installation"]}], "detection_methods": [{"method": "Automated Static Analysis"}, {"method": "Automated Dynamic Analysis", "description": "Automated dynamic analysis may not be able to find interfaces that are protected by authorization checks, even if those checks contain weaknesses."}, {"method": "Manual Analysis"}], "observed_examples": [{"cve": "CVE-2025-24839", "description": "collaboration platform allows attacker to access an AI bot by using a plugin to set a critical property"}, {"cve": "CVE-2025-32796", "description": "LLM application development platform allows non-admin users to enable or disable apps using certain API endpoints"}, {"cve": "CVE-2021-39155", "description": "Chain: A microservice integration and management platform compares the hostname in the HTTP Host header in a case-sensitive way (CWE-178, CWE-1289), a..."}, {"cve": "CVE-2019-15900", "description": "Chain: sscanf() call is used to check if a username and group exists, but the return value of sscanf() call is not checked (CWE-252), causing an unini..."}, {"cve": "CVE-2009-2213", "description": "Gateway uses default \"Allow\" configuration for its authorization settings."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Server", "Database Server", "Not Technology-Specific"]}}, "87": {"name": "Improper Neutralization of Alternate XSS Syntax", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not neutralize or incorrectly neutralizes user-controlled input for alternate script syntax.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Read Application Data", "Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Resolve all input to absolute or canonical representations before processing.", "phase": ["Implementation"]}, {"description": "Carefully check each input parameter against a rigorous positive specification (allowlist) defining the specific characters and format allowed. All input should be neutralized, not just parameters that the user is supposed to specify, but all data in the request, including tag attributes, hidden fie...", "phase": ["Implementation"]}, {"description": "With Struts, write all data from form beans with the bean's filter attribute set to true.", "phase": ["Implementation"]}], "observed_examples": [{"cve": "CVE-2002-0738", "description": "XSS using \"&={script}\"."}], "platforms": {"languages": ["Not Language-Specific"]}}, "88": {"name": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product constructs a string for a command to be executed by a separate component\nin another control sphere, but it does not properly delimit the\nintended arguments, options, or switches within that command string.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Other"], "impact": ["Execute Unauthorized Code or Commands", "Alter Execution Logic", "Read Application Data", "Modify Application Data"]}], "mitigations": [{"description": "Where possible, avoid building a single string that contains the command and its arguments.  Some languages or frameworks have functions that support specifying independent arguments, e.g. as an array, which is used to automatically perform the appropriate quoting or escaping while building the comm...", "phase": ["Implementation"]}, {"description": "Understand all the potential areas where untrusted inputs can enter your product: parameters or arguments, cookies, anything read from the network, environment variables, request headers as well as content, URL components, e-mail, files, databases, and any external systems that provide data to the a...", "phase": ["Architecture and Design"]}, {"description": "Directly convert your input type into the expected data type, such as using a conversion function that translates a string into a number. After converting to the expected data type, ensure that the input's values fall within the expected range of allowable values and that multi-field consistencies a...", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-36069", "description": "Python-based dependency management tool avoids OS command injection  when generating Git commands but allows  injection of optional arguments with inp..."}, {"cve": "CVE-1999-0113", "description": "Canonical Example - \"-froot\" argument is passed on to another program, where the \"-f\" causes execution as user \"root\""}, {"cve": "CVE-2001-0150", "description": "Web browser executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute ar..."}, {"cve": "CVE-2001-0667", "description": "Web browser allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into ..."}, {"cve": "CVE-2002-0985", "description": "Argument injection vulnerability in the mail function for PHP may allow attackers to bypass safe mode restrictions and modify command line arguments t..."}], "platforms": {"languages": ["Not Language-Specific", "PHP"], "technologies": ["Not Technology-Specific"]}}, "89": {"name": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Authentication"], "impact": ["Gain Privileges or Assume Identity", "Bypass Protection Mechanism"]}, {"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Integrity"], "impact": ["Modify Application Data"]}], "mitigations": [{"description": "For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-s...", "phase": ["Architecture and Design"]}, {"description": "When the set of acceptable objects, such as filenames or URLs, is limited or known, create a mapping from a set of fixed input values (such as numeric IDs) to the actual filenames or URLs, and reject all other inputs.", "phase": ["Architecture and Design"]}, {"description": "Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide d...", "phase": ["Operation"]}], "detection_methods": [{"method": "Automated Static Analysis"}, {"method": "Automated Dynamic Analysis", "description": "This weakness can be detected using dynamic tools and techniques that interact with the software using large test suites with many diverse inputs, such as fuzz testing (fuzzing), robustness testing, a..."}, {"method": "Manual Analysis", "description": "Manual analysis can be useful for finding this weakness, but it might not achieve desired code coverage within limited time constraints. This becomes difficult for weaknesses that must be considered f..."}], "observed_examples": [{"cve": "CVE-2024-6847", "description": "SQL injection in AI chatbot via a conversation message"}, {"cve": "CVE-2025-26794", "description": "SQL injection in e-mail agent through SQLite integration"}, {"cve": "CVE-2023-32530", "description": "SQL injection in security product dashboard using crafted certificate fields"}, {"cve": "CVE-2021-42258", "description": "SQL injection in time and billing software, as exploited in the wild per CISA KEV."}, {"cve": "CVE-2021-27101", "description": "SQL injection in file-transfer system via a crafted Host header, as exploited in the wild per CISA KEV."}], "platforms": {"languages": ["Not Language-Specific", "SQL"], "technologies": ["Database Server"]}}, "9": {"name": "J2EE Misconfiguration: Weak Access Permissions for EJB Methods", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "If elevated access rights are assigned to EJB methods, then an attacker can take advantage of the permissions to exploit the product.", "extended_description": "If the EJB deployment descriptor contains one or more method permissions that grant access to the special ANYONE role, it indicates that access control for the application has not been fully thought through or that the application is structured in such a way that reasonable access control restrictions are impossible.", "consequences": [{"scope": ["Other"], "impact": ["Other"]}], "mitigations": [{"description": "Follow the principle of least privilege when assigning access rights to EJB methods. Permission to invoke EJB methods should not be granted to the ANYONE role.", "phase": ["Architecture and Design", "System Configuration"]}], "platforms": {"languages": ["Java"]}}, "90": {"name": "Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product constructs all or part of an LDAP query using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended LDAP query when it is sent to a downstream component.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands", "Read Application Data", "Modify Application Data"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2021-41232", "description": "Chain: authentication routine in Go-based agile development product does not escape user name (CWE-116), allowing LDAP injection (CWE-90)"}, {"cve": "CVE-2005-2301", "description": "Server does not properly escape LDAP queries, which allows remote attackers to cause a DoS and possibly conduct an LDAP injection attack."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Database Server"]}}, "908": {"name": "Use of Uninitialized Resource", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses or accesses a resource that has not been initialized.", "extended_description": "When a resource has not been properly initialized, the product may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the product.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory", "Read Application Data"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Explicitly initialize the resource before use. If this is performed through an API function or standard procedure, follow all required steps.", "phase": ["Implementation"]}, {"description": "Pay close attention to complex conditionals that affect initialization, since some branches might not perform the initialization.", "phase": ["Implementation"]}, {"description": "Avoid race conditions (CWE-362) during initialization routines.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2019-9805", "description": "Chain: Creation of the packet client occurs before initialization is complete (CWE-696) resulting in a read from uninitialized memory (CWE-908), causi..."}, {"cve": "CVE-2008-4197", "description": "Use of uninitialized memory may allow code execution."}, {"cve": "CVE-2008-2934", "description": "Free of an uninitialized pointer leads to crash and possible code execution."}, {"cve": "CVE-2008-0063", "description": "Product does not clear memory contents when generating an error message, leading to information leak."}, {"cve": "CVE-2008-0062", "description": "Lack of initialization triggers NULL pointer dereference or double-free."}], "platforms": {"languages": ["Not Language-Specific"]}}, "909": {"name": "Missing Initialization of Resource", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not initialize a critical resource.", "extended_description": "Many resources require initialization before they can be properly used. If a resource is not initialized, it could contain unpredictable or expired data, or it could be initialized to defaults that are invalid. This can have security implications when the resource is expected to have certain properties or values.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Memory", "Read Application Data"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "mitigations": [{"description": "Explicitly initialize the resource before use. If this is performed through an API function or standard procedure, follow all specified steps.", "phase": ["Implementation"]}, {"description": "Pay close attention to complex conditionals that affect initialization, since some branches might not perform the initialization.", "phase": ["Implementation"]}, {"description": "Avoid race conditions (CWE-362) during initialization routines.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2020-20739", "description": "A variable that has its value set in a conditional statement is sometimes used when the conditional fails, sometimes causing data leakage"}, {"cve": "CVE-2005-1036", "description": "Chain: Bypass of access restrictions due to improper authorization (CWE-862) of a user results from an improperly initialized (CWE-909) I/O permission..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "91": {"name": "XML Injection (aka Blind XPath Injection)", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.", "extended_description": "Within XML, special elements could include reserved words or characters such as \"<\", \">\", \"\"\", and \"&\", which could then be used to add new data or modify XML syntax.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands", "Read Application Data", "Modify Application Data"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"]}}, "910": {"name": "Use of Expired File Descriptor", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses or accesses a file descriptor after it has been closed.", "extended_description": "After a file descriptor for a particular file or device has been released, it can be reused. The code might not write to the original file, since the reused file descriptor might reference a different file or device.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Files or Directories"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["C", "C++", "Not Language-Specific"]}}, "911": {"name": "Improper Update of Reference Count", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a reference count to manage a resource, but it does not update or incorrectly updates the reference count.", "extended_description": "Reference counts can be used when tracking how many objects contain a reference to a particular resource, such as in memory management or garbage collection. When the reference count reaches zero, the resource can be de-allocated or reused because there are no more objects that use it. If the reference count accidentally reaches zero, then the resource might be released too soon, even though it is still in use. If all objects no longer use the resource, but the reference count is not zero, then ...", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (Memory)", "DoS: Resource Consumption (Other)"]}, {"scope": ["Availability"], "impact": ["DoS: Crash, Exit, or Restart"]}], "observed_examples": [{"cve": "CVE-2002-0574", "description": "chain: reference count is not decremented, leading to memory leak in OS by sending ICMP packets."}, {"cve": "CVE-2004-0114", "description": "Reference count for shared memory not decremented when a function fails, potentially allowing unprivileged users to read kernel memory."}, {"cve": "CVE-2006-3741", "description": "chain: improper reference count tracking leads to file descriptor consumption"}, {"cve": "CVE-2007-1383", "description": "chain: integer overflow in reference counter causes the same variable to be destroyed twice."}, {"cve": "CVE-2007-1700", "description": "Incorrect reference count calculation leads to improper object destruction and code execution."}], "platforms": {"languages": ["C", "C++", "Not Language-Specific"]}}, "912": {"name": "Hidden Functionality", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.", "extended_description": "Hidden functionality can take many forms, such as intentionally malicious code, \"Easter Eggs\" that contain extraneous functionality such as games, developer-friendly shortcuts that reduce maintenance or support costs such as hard-coded accounts, etc. From a security perspective, even when the functionality is not intentionally malicious or damaging, it can increase the product's attack surface and expose additional weaknesses beyond what is already exposed by the intended functionality. Even if ...", "consequences": [{"scope": ["Other", "Integrity"], "impact": ["Varies by Context", "Alter Execution Logic"]}], "mitigations": [{"description": "Always verify the integrity of the product that is being installed.", "phase": ["Installation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Conduct a code coverage analysis using live testing, then closely inspect any code that is not covered."}], "observed_examples": [{"cve": "CVE-2022-31260", "description": "Chain: a digital asset management program has an undisclosed backdoor in the legacy version of a PHP script (CWE-912) that could allow an unauthentica..."}, {"cve": "CVE-2022-3203", "description": "A wireless access point manual specifies that the only method of configuration is via web interface (CWE-1059), but there is an undisclosed telnet ser..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "ICS/OT"]}}, "913": {"name": "Improper Control of Dynamically-Managed Code Resources", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.", "extended_description": "Many languages offer powerful features that allow the programmer to dynamically create or modify existing code, or resources used by code such as variables and objects. While these features can offer significant flexibility and reduce development time, they can be extremely dangerous if attackers can directly influence these code resources in unexpected ways.", "consequences": [{"scope": ["Integrity"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Other", "Integrity"], "impact": ["Varies by Context", "Alter Execution Logic"]}], "mitigations": [{"description": "For any externally-influenced input, check the input against an allowlist of acceptable values.", "phase": ["Implementation"]}, {"description": "Refactor the code so that it does not need to be dynamically managed.", "phase": ["Implementation", "Architecture and Design"]}], "detection_methods": [{"method": "Fuzzing", "description": "Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with rand..."}], "observed_examples": [{"cve": "CVE-2022-2054", "description": "Python compiler uses eval() to execute malicious strings as Python code."}, {"cve": "CVE-2018-1000613", "description": "Cryptography API uses unsafe reflection when deserializing a private key"}, {"cve": "CVE-2015-8103", "description": "Deserialization issue in commonly-used Java library allows remote execution."}, {"cve": "CVE-2006-7079", "description": "Chain: extract used for register_globals compatibility layer, enables path traversal (CWE-22)"}, {"cve": "CVE-2012-2055", "description": "Source version control product allows modification of trusted key using mass assignment."}], "platforms": {"languages": ["Not Language-Specific", "Interpreted"]}}, "914": {"name": "Improper Control of Dynamically-Identified Variables", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product does not properly restrict reading from or writing to dynamically-identified variables.", "extended_description": "Many languages offer powerful features that allow the programmer to access arbitrary variables that are specified by an input string. While these features can offer significant flexibility and reduce development time, they can be extremely dangerous if attackers can modify unintended variables that have security implications.", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}, {"scope": ["Integrity"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Other", "Integrity"], "impact": ["Varies by Context", "Alter Execution Logic"]}], "mitigations": [{"description": "For any externally-influenced input, check the input against an allowlist of internal program variables that are allowed to be modified.", "phase": ["Implementation"]}, {"description": "Refactor the code so that internal program variables do not need to be dynamically identified.", "phase": ["Implementation", "Architecture and Design"]}], "observed_examples": [{"cve": "CVE-2006-7135", "description": "extract issue enables file inclusion"}, {"cve": "CVE-2006-7079", "description": "Chain: extract used for register_globals compatibility layer, enables path traversal (CWE-22)"}, {"cve": "CVE-2007-0649", "description": "extract() buried in include files makes post-disclosure analysis confusing; original report had seemed incorrect."}, {"cve": "CVE-2006-6661", "description": "extract() enables static code injection"}, {"cve": "CVE-2006-2828", "description": "import_request_variables() buried in include files makes post-disclosure analysis confusing"}], "platforms": {"languages": ["Not Language-Specific", "Interpreted"]}}, "915": {"name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}, {"scope": ["Integrity"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Other", "Integrity"], "impact": ["Varies by Context", "Alter Execution Logic"]}], "mitigations": [{"description": "If available, use the signing/sealing features of the programming language to assure that deserialized data has not been tainted. For example, a hash-based message authentication code (HMAC) could be used to ensure that data has not been modified.", "phase": ["Architecture and Design", "Implementation"]}, {"description": "For any externally-influenced input, check the input against an allowlist of internal object attributes or fields that are allowed to be modified.", "phase": ["Implementation"]}, {"description": "Refactor the code so that object attributes or fields do not need to be dynamically identified, and only expose getter/setter functionality for the intended attributes.", "phase": ["Implementation", "Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2024-3283", "description": "Application for using LLMs allows modification of a sensitive variable using mass assignment."}, {"cve": "CVE-2012-2054", "description": "Mass assignment allows modification of arbitrary attributes using modified URL."}, {"cve": "CVE-2012-2055", "description": "Source version control product allows modification of trusted key using mass assignment."}, {"cve": "CVE-2008-7310", "description": "Attackers can bypass payment step in e-commerce product."}, {"cve": "CVE-2013-1465", "description": "Use of PHP unserialize function on untrusted input allows attacker to modify application configuration."}], "platforms": {"languages": ["Ruby", "ASP.NET", "PHP", "Python", "Not Language-Specific"], "technologies": ["Not Technology-Specific"]}}, "916": {"name": "Use of Password Hash With Insufficient Computational Effort", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism", "Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "When using industry-approved techniques, use them correctly. Don't cut corners by skipping resource-intensive steps (CWE-325). These steps are often essential for preventing common attacks.", "phase": ["Implementation", "Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis - Binary or Bytecode"}, {"method": "Manual Static Analysis - Binary or Bytecode"}, {"method": "Manual Static Analysis - Source Code"}], "observed_examples": [{"cve": "CVE-2008-1526", "description": "Router does not use a salt with a hash, making it easier to crack passwords."}, {"cve": "CVE-2006-1058", "description": "Router does not use a salt with a hash, making it easier to crack passwords."}, {"cve": "CVE-2008-4905", "description": "Blogging software uses a hard-coded salt when calculating a password hash."}, {"cve": "CVE-2002-1657", "description": "Database server uses the username for a salt when encrypting passwords, simplifying brute force attacks."}, {"cve": "CVE-2001-0967", "description": "Server uses a constant salt when encrypting passwords, simplifying brute force attacks."}], "platforms": {"languages": ["Not Language-Specific"]}}, "917": {"name": "Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.", "extended_description": "Frameworks such as Java Server Page (JSP) allow a developer to insert executable expressions within otherwise-static content. When the developer is not aware of the executable nature of these expressions and/or does not disable them, then if an attacker can inject expressions, this could lead to code execution or other unexpected behaviors.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Integrity"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Avoid adding user-controlled data into an expression interpreter when possible.", "phase": ["Architecture and Design"]}, {"description": "The framework or tooling might allow the developer to disable or deactivate the processing of EL expressions, such as setting the isELIgnored attribute for a JSP page to \"true\".", "phase": ["System Configuration", "Operation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2021-44228", "description": "Product does not neutralize ${xyz} style expressions, allowing remote code execution. (log4shell vulnerability in log4j)"}], "platforms": {"languages": ["Java"]}}, "918": {"name": "Server-Side Request Forgery (SSRF)", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Integrity"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2024-3095", "description": "SSRF in LLM application development framework because the URL retriever allows connections to local addresses using a crafted Location header"}, {"cve": "CVE-2023-32786", "description": "Chain: LLM integration framework has prompt injection\n\t     (CWE-1427) that allows an attacker to force the service to retrieve\n\t     data from an arb..."}, {"cve": "CVE-2021-26855", "description": "Server Side Request Forgery (SSRF) in mail server, as exploited in the wild per CISA KEV."}, {"cve": "CVE-2021-21973", "description": "Server Side Request Forgery in cloud platform, as exploited in the wild per CISA KEV."}, {"cve": "CVE-2016-4029", "description": "Chain: incorrect validation of intended decimal-based IP address format (CWE-1286) enables parsing of octal or hexadecimal formats (CWE-1389), allowin..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "AI/ML", "Web Server"]}}, "92": {"name": "DEPRECATED: Improper Sanitization of Custom Special Characters", "abstraction": "Base", "mapping": "PROHIBITED", "structure": "Simple", "description": "This entry has been deprecated. It originally came from PLOVER, which sometimes defined \"other\" and \"miscellaneous\" categories in order to satisfy exhaustiveness requirements for taxonomies. Within the context of CWE, the use of a more abstract entry is preferred in mapping situations. CWE-75 is a more appropriate mapping."}, "920": {"name": "Improper Restriction of Power Consumption", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product operates in an environment in which power is a limited resource that cannot be automatically replenished, but the product does not properly restrict the amount of power that its operation consumes.", "consequences": [{"scope": ["Availability"], "impact": ["DoS: Resource Consumption (Other)", "DoS: Crash, Exit, or Restart"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Mobile"]}}, "921": {"name": "Storage of Sensitive Data in a Mechanism without Access Control", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product stores sensitive information in a file system or device that does not have built-in access control.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data", "Read Files or Directories"]}, {"scope": ["Integrity"], "impact": ["Modify Application Data", "Modify Files or Directories"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Mobile"]}}, "922": {"name": "Insecure Storage of Sensitive Information", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product stores sensitive information without properly limiting read or write access by unauthorized actors.", "extended_description": "If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data", "Read Files or Directories"]}, {"scope": ["Integrity"], "impact": ["Modify Application Data", "Modify Files or Directories"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2009-2272", "description": "password and username stored in cleartext in a cookie"}], "platforms": {"languages": ["Not Language-Specific"]}}, "923": {"name": "Improper Restriction of Communication Channel to Intended Endpoints", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.", "consequences": [{"scope": ["Integrity", "Confidentiality"], "impact": ["Gain Privileges or Assume Identity"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-30319", "description": "S-bus functionality in a home automation product performs access control using an IP allowlist, which can be bypassed by a forged IP address."}, {"cve": "CVE-2022-22547", "description": "A troubleshooting tool exposes a web server on a random port between 9000-65535 that could be used for information gathering"}, {"cve": "CVE-2022-4390", "description": "A WAN interface on a router has firewall restrictions enabled for IPv4, but it does not for IPv6, which is enabled by default"}, {"cve": "CVE-2012-2292", "description": "Product has a Silverlight cross-domain policy that does not restrict access to another application, which allows remote attackers to bypass the Same O..."}, {"cve": "CVE-2012-5810", "description": "Mobile banking application does not verify hostname, leading to financial loss."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Not Technology-Specific", "Web Based", "Web Server"]}}, "924": {"name": "Improper Enforcement of Message Integrity During Transmission in a Communication Channel", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product establishes a communication channel with an endpoint and receives a message from that endpoint, but it does not sufficiently ensure that the message was not modified during transmission.", "extended_description": "Attackers might be able to modify the message and spoof the endpoint by interfering with the data as it crosses the network or by redirecting the connection to a system under their control.", "consequences": [{"scope": ["Integrity", "Confidentiality"], "impact": ["Gain Privileges or Assume Identity"]}], "platforms": {"languages": ["Not Language-Specific"]}}, "925": {"name": "Improper Verification of Intent by Broadcast Receiver", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The Android application uses a Broadcast Receiver that receives an Intent but does not properly verify that the Intent came from an authorized source.", "extended_description": "Certain types of Intents, identified by action string, can only be broadcast by the operating system itself, not by third-party applications. However, when an application registers to receive these implicit system intents, it is also registered to receive any explicit intents. While a malicious application cannot send an implicit system intent, it can send an explicit intent to the target application, which may assume that any received intent is a valid implicit system intent and not an explicit...", "consequences": [{"scope": ["Integrity"], "impact": ["Gain Privileges or Assume Identity"]}], "mitigations": [{"description": "Before acting on the Intent, check the Intent Action to make sure it matches the expected System action.", "phase": ["Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Mobile"]}}, "926": {"name": "Improper Export of Android Application Components", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.", "consequences": [{"scope": ["Availability", "Integrity"], "impact": ["Unexpected State", "DoS: Crash, Exit, or Restart", "DoS: Instability", "Varies by Context"]}, {"scope": ["Availability", "Integrity"], "impact": ["Unexpected State", "Gain Privileges or Assume Identity", "DoS: Crash, Exit, or Restart", "DoS: Instability", "Varies by Context"]}, {"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data"]}], "mitigations": [{"description": "If they do not need to be shared by other applications, explicitly mark components with android:exported=\"false\" in the application manifest.", "phase": ["Build and Compilation"]}, {"description": "If you only intend to use exported components between related apps under your control, use android:protectionLevel=\"signature\" in the xml manifest to restrict access to applications signed by you.", "phase": ["Build and Compilation"]}, {"description": "Limit Content Provider permissions (read/write) as appropriate.", "phase": ["Build and Compilation", "Architecture and Design"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Mobile"]}}, "927": {"name": "Use of Implicit Intent for Sensitive Communication", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The Android application uses an implicit intent for transmitting sensitive data to other applications.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Application Data"]}, {"scope": ["Integrity"], "impact": ["Varies by Context"]}], "mitigations": [{"description": "If the application only requires communication with its own components, then the destination is always known, and an explicit intent could be used.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2022-4903", "description": "An Android application does not use FLAG_IMMUTABLE when creating a PendingIntent."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Mobile"]}}, "93": {"name": "Improper Neutralization of CRLF Sequences ('CRLF Injection')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.", "consequences": [{"scope": ["Integrity"], "impact": ["Modify Application Data"]}], "mitigations": [{"description": "Avoid using CRLF as a special sequence.", "phase": ["Implementation"]}, {"description": "Appropriately filter or quote CRLF sequences in user-controlled input.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2002-1771", "description": "CRLF injection enables spam proxy (add mail headers) using email address or name."}, {"cve": "CVE-2002-1783", "description": "CRLF injection in API function arguments modify headers for outgoing requests."}, {"cve": "CVE-2004-1513", "description": "Spoofed entries in web server log file via carriage returns"}, {"cve": "CVE-2006-4624", "description": "Chain: inject fake log entries with fake timestamps using CRLF injection"}, {"cve": "CVE-2005-1951", "description": "Chain: Application accepts CRLF in an object ID, allowing HTTP response splitting."}], "platforms": {"languages": ["Not Language-Specific"]}}, "939": {"name": "Improper Authorization in Handler for Custom URL Scheme", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a handler for a custom URL scheme, but it does not properly restrict which actors can invoke the handler using the scheme.", "extended_description": "Mobile platforms and other architectures allow the use of custom URL schemes to facilitate communication between applications. In the case of iOS, this is the only method to do inter-application communication. The implementation is at the developer's discretion which may open security flaws in the application. An example could be potentially dangerous functionality such as modifying files through a custom URL scheme.", "consequences": [{"scope": ["Access Control", "Other"], "impact": ["Gain Privileges or Assume Identity", "Varies by Context", "Bypass Protection Mechanism"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2013-5725", "description": "URL scheme has action replace which requires no user prompt and allows remote attackers to perform undesired actions."}, {"cve": "CVE-2013-5726", "description": "URL scheme has action follow and favorite which allows remote attackers to force user to perform undesired actions."}], "platforms": {"technologies": ["Mobile"]}}, "94": {"name": "Improper Control of Generation of Code ('Code Injection')", "abstraction": "Base", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Non-Repudiation"], "impact": ["Hide Activities"]}], "mitigations": [{"description": "Refactor your program so that you do not have to dynamically generate code.", "phase": ["Architecture and Design"]}, {"description": "Use automated static analysis tools that target this type of weakness. Many modern techniques use data flow analysis to minimize the number of false positives. This is not a perfect solution, since 100% accuracy and coverage are not feasible.", "phase": ["Testing"]}, {"description": "Use dynamic tools and techniques that interact with the product using large test suites with many diverse inputs, such as fuzz testing (fuzzing), robustness testing, and fault injection. The product's operation may slow down, but it should not become unstable, crash, or generate incorrect results.", "phase": ["Testing"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2023-29374", "description": "Math component in an LLM framework translates user input into a Python\n\t\t\t   expression that is input into the Python exec() method, allowing code\n\t\t\t..."}, {"cve": "CVE-2024-5565", "description": "Python-based library uses an LLM prompt containing user input to\n\t\t\t   dynamically generate code that is then fed as input into the Python\n\t\t\t   exec(..."}, {"cve": "CVE-2024-4181", "description": "Framework for LLM applications allows eval injection via a crafted response from a hosting provider."}, {"cve": "CVE-2022-2054", "description": "Python compiler uses eval() to execute malicious strings as Python code."}, {"cve": "CVE-2021-22204", "description": "Chain: regex in EXIF processor code does not correctly determine where a string ends (CWE-625), enabling eval injection (CWE-95), as exploited in the ..."}], "platforms": {"languages": ["Interpreted"], "technologies": ["AI/ML"]}}, "940": {"name": "Improper Verification of Source of a Communication Channel", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.", "extended_description": "When an attacker can successfully establish a communication channel from an untrusted origin, the attacker may be able to gain privileges and access unexpected functionality.", "consequences": [{"scope": ["Access Control", "Other"], "impact": ["Gain Privileges or Assume Identity", "Varies by Context", "Bypass Protection Mechanism"]}], "observed_examples": [{"cve": "CVE-2000-1218", "description": "DNS server can accept DNS updates from hosts that it did not query, leading to cache poisoning"}, {"cve": "CVE-2005-0877", "description": "DNS server can accept DNS updates from hosts that it did not query, leading to cache poisoning"}, {"cve": "CVE-2001-1452", "description": "DNS server caches glue records received from non-delegated name servers"}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Mobile"]}}, "941": {"name": "Incorrectly Specified Destination in a Communication Channel", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product creates a communication channel to initiate an outgoing request to an actor, but it does not correctly specify the intended destination for that actor.", "consequences": [{"scope": ["Access Control", "Other"], "impact": ["Gain Privileges or Assume Identity", "Varies by Context", "Bypass Protection Mechanism"]}], "observed_examples": [{"cve": "CVE-2013-5211", "description": "composite: NTP feature generates large responses (high amplification factor) with spoofed UDP source addresses."}, {"cve": "CVE-1999-0513", "description": "Classic \"Smurf\" attack, using spoofed ICMP packets to broadcast addresses."}, {"cve": "CVE-1999-1379", "description": "DNS query with spoofed source address causes more traffic to be returned to spoofed address than was sent by the attacker."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Mobile"]}}, "942": {"name": "Permissive Cross-domain Security Policy with Untrusted Domains", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product uses a web-client protection\n         mechanism such as a Content Security Policy (CSP) or\n         cross-domain policy file, but the policy includes untrusted\n         domains with which the web client is allowed to\n         communicate.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Execute Unauthorized Code or Commands", "Bypass Protection Mechanism", "Read Application Data", "Varies by Context"]}], "mitigations": [{"description": "Define a restrictive Content Security Policy [REF-1486] or cross-domain policy file.", "phase": ["Architecture and Design", "Operation"]}, {"description": "Avoid using wildcards in the CSP / cross-domain policy file. Any domain matching the wildcard expression will be implicitly trusted, and can perform two-way interaction with the target server.", "phase": ["Architecture and Design", "Operation"]}, {"description": "For Flash, modify crossdomain.xml to use meta-policy options such as 'master-only' or 'none' to reduce the possibility of an attacker planting extraneous cross-domain policy files on a server.", "phase": ["Architecture and Design", "Operation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2012-2292", "description": "Product has a Silverlight cross-domain policy that does not restrict access to another application, which allows remote attackers to bypass the Same O..."}, {"cve": "CVE-2014-2049", "description": "The default Flash Cross Domain policies in a product allows remote attackers to access user files."}, {"cve": "CVE-2007-6243", "description": "Chain: Adobe Flash Player does not sufficiently restrict the interpretation and usage of cross-domain policy files, which makes it easier for remote a..."}, {"cve": "CVE-2008-4822", "description": "Chain: Adobe Flash Player and earlier does not properly interpret policy files, which allows remote attackers to bypass a non-root domain policy."}, {"cve": "CVE-2010-3636", "description": "Chain: Adobe Flash Player does not properly handle unspecified encodings during the parsing of a cross-domain policy file, which allows remote web ser..."}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "943": {"name": "Improper Neutralization of Special Elements in Data Query Logic", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability", "Access Control"], "impact": ["Bypass Protection Mechanism", "Read Application Data", "Modify Application Data", "Varies by Context"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2024-50672", "description": "NoSQL injection in product for building eLearning courses allows password resets using a query processed by the Mongoose find function"}, {"cve": "CVE-2021-20736", "description": "NoSQL injection in team collaboration product"}, {"cve": "CVE-2020-35666", "description": "NoSQL injection in a PaaS platform using a MongoDB operator"}, {"cve": "CVE-2014-2503", "description": "Injection using Documentum Query Language (DQL)"}, {"cve": "CVE-2014-2508", "description": "Injection using Documentum Query Language (DQL)"}], "platforms": {"languages": ["Not Language-Specific"]}}, "95": {"name": "Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. \"eval\").", "likelihood_of_exploit": "Medium", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Files or Directories", "Read Application Data"]}, {"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Integrity", "Confidentiality", "Availability", "Other"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Non-Repudiation"], "impact": ["Hide Activities"]}], "mitigations": [{"description": "If possible, refactor your code so that it does not need to use eval() at all.", "phase": ["Architecture and Design", "Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2024-4181", "description": "Framework for LLM applications allows eval injection via a crafted response from a hosting provider."}, {"cve": "CVE-2022-2054", "description": "Python compiler uses eval() to execute malicious strings as Python code."}, {"cve": "CVE-2021-22204", "description": "Chain: regex in EXIF processor code does not correctly determine where a string ends (CWE-625), enabling eval injection (CWE-95), as exploited in the ..."}, {"cve": "CVE-2021-22205", "description": "Chain: backslash followed by a newline can bypass a validation step (CWE-20), leading to eval injection (CWE-95), as exploited in the wild per CISA KE..."}, {"cve": "CVE-2008-5071", "description": "Eval injection in PHP program."}], "platforms": {"languages": ["Java", "JavaScript", "Python", "Perl", "PHP", "Ruby", "Interpreted"], "technologies": ["AI/ML"]}}, "96": {"name": "Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')", "abstraction": "Base", "mapping": "ALLOWED", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before inserting the input into an executable resource, such as a library, configuration file, or template.", "consequences": [{"scope": ["Confidentiality"], "impact": ["Read Files or Directories", "Read Application Data"]}, {"scope": ["Access Control"], "impact": ["Bypass Protection Mechanism"]}, {"scope": ["Access Control"], "impact": ["Gain Privileges or Assume Identity"]}, {"scope": ["Integrity", "Confidentiality", "Availability", "Other"], "impact": ["Execute Unauthorized Code or Commands"]}, {"scope": ["Non-Repudiation"], "impact": ["Hide Activities"]}], "mitigations": [{"description": "Perform proper output validation and escaping to neutralize all code syntax from data written to code files.", "phase": ["Implementation"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2002-0495", "description": "Perl code directly injected into CGI library file from parameters to another CGI program."}, {"cve": "CVE-2005-1876", "description": "Direct PHP code injection into supporting template file."}, {"cve": "CVE-2005-1894", "description": "Direct code injection into PHP script that can be accessed by attacker."}, {"cve": "CVE-2003-0395", "description": "PHP code from User-Agent HTTP header directly inserted into log file implemented as PHP script."}, {"cve": "CVE-2007-6652", "description": "chain: execution after redirect allows non-administrator to perform static code injection."}], "platforms": {"languages": ["PHP", "Perl", "Interpreted"]}}, "97": {"name": "Improper Neutralization of Server-Side Includes (SSI) Within a Web Page", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The product generates a web page, but does not neutralize or incorrectly neutralizes user-controllable input that could be interpreted as a server-side include (SSI) directive.", "consequences": [{"scope": ["Confidentiality", "Integrity", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "platforms": {"languages": ["Not Language-Specific"], "technologies": ["Web Based", "Web Server"]}}, "98": {"name": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')", "abstraction": "Variant", "mapping": "ALLOWED", "structure": "Simple", "description": "The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in \"require,\" \"include,\" or similar functions.", "extended_description": "In certain versions and configurations of PHP, this can allow an attacker to specify a URL to a remote location from which the product will obtain the code to execute. In other cases in association with path traversal, the attacker can specify a local file that may contain executable statements that can be parsed by PHP.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Integrity", "Confidentiality", "Availability"], "impact": ["Execute Unauthorized Code or Commands"]}], "mitigations": [{"description": "Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482].", "phase": ["Architecture and Design"]}, {"description": "For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-s...", "phase": ["Architecture and Design"]}, {"description": "Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the s...", "phase": ["Architecture and Design", "Operation"]}], "detection_methods": [{"method": "Manual Analysis", "description": "Manual white-box analysis can be very effective for finding this issue, since there is typically a relatively small number of include or require statements in each program."}, {"method": "Automated Static Analysis"}], "observed_examples": [{"cve": "CVE-2004-0285", "description": "Modification of assumed-immutable configuration variable in include file allows file inclusion via direct request."}, {"cve": "CVE-2004-0030", "description": "Modification of assumed-immutable configuration variable in include file allows file inclusion via direct request."}, {"cve": "CVE-2004-0068", "description": "Modification of assumed-immutable configuration variable in include file allows file inclusion via direct request."}, {"cve": "CVE-2005-2157", "description": "Modification of assumed-immutable configuration variable in include file allows file inclusion via direct request."}, {"cve": "CVE-2005-2162", "description": "Modification of assumed-immutable configuration variable in include file allows file inclusion via direct request."}], "platforms": {"languages": ["PHP"], "technologies": ["Web Based", "Web Server"]}}, "99": {"name": "Improper Control of Resource Identifiers ('Resource Injection')", "abstraction": "Class", "mapping": "ALLOWED-WITH-REVIEW", "structure": "Simple", "description": "The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control.", "likelihood_of_exploit": "High", "consequences": [{"scope": ["Confidentiality", "Integrity"], "impact": ["Read Application Data", "Modify Application Data", "Read Files or Directories", "Modify Files or Directories"]}], "detection_methods": [{"method": "Automated Static Analysis", "description": "Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without havin..."}], "observed_examples": [{"cve": "CVE-2013-4787", "description": "chain: mobile OS verifies cryptographic signature of file in an archive, but then installs a different file with the same name that is also listed in ..."}], "platforms": {"languages": ["Not Language-Specific"]}}}