Umbra Wiki weakness weakness/CWE-528
Back to wiki

CWE-528 — Exposure of Core Dump File to an Unauthorized Control Sphere

provenance: imported · CWE: CWE-528

CWE-528: Exposure of Core Dump File to an Unauthorized Control Sphere

MITRE CWE weakness

Kind Weakness
Abstraction Variant
Status Draft
Likelihood of exploit

Description

The product generates a core dump file in a directory, archive, or other resource that is stored, transferred, or otherwise made accessible to unauthorized actors.

Common consequences

  • Confidentiality: Read Application Data, Read Files or Directories

Mitigations

System Configuration — Protect the core dump files from unauthorized access.

References

  • CWE page: https://cwe.mitre.org/data/definitions/528.html
  • CWE list: https://cwe.mitre.org/data/index.html