CWE-348 — Use of Less Trusted Source
CWE-348: Use of Less Trusted Source
MITRE CWE weakness
| Kind | Weakness |
| Abstraction | Base |
| Status | Draft |
| Likelihood of exploit | — |
Description
The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.
Common consequences
- Access Control: Bypass Protection Mechanism, Gain Privileges or Assume Identity
Mitigations
(none listed)
References
- CWE page: https://cwe.mitre.org/data/definitions/348.html
- CWE list: https://cwe.mitre.org/data/index.html