CWE-595 — Comparison of Object References Instead of Object Contents
CWE-595: Comparison of Object References Instead of Object Contents
MITRE CWE weakness
| Kind | Weakness |
| Abstraction | Variant |
| Status | Incomplete |
| Likelihood of exploit | — |
Description
The product compares object references instead of the contents of the objects themselves, preventing it from detecting equivalent objects.
For example, in Java, comparing objects using == usually produces deceptive results, since the == operator compares object references rather than values; often, this means that using == for strings is actually comparing the strings' references, not their values.
Common consequences
- Other: Varies by Context
Mitigations
Implementation — In Java, use the equals() method to compare objects instead of the == operator. If using ==, it is important for performance reasons that your objects are created by a static factory, not by a constructor.
References
- CWE page: https://cwe.mitre.org/data/definitions/595.html
- CWE list: https://cwe.mitre.org/data/index.html