Umbra Wiki weakness weakness/CWE-610
Back to wiki

CWE-610 — Externally Controlled Reference to a Resource in Another Sphere

provenance: imported · CWE: CWE-610

CWE-610: Externally Controlled Reference to a Resource in Another Sphere

MITRE CWE weakness

Kind Weakness
Abstraction Class
Status Draft
Likelihood of exploit

Description

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Common consequences

  • Confidentiality, Integrity: Read Application Data, Modify Application Data
  • Access Control: Gain Privileges or Assume Identity

Mitigations

(none listed)

References

  • CWE page: https://cwe.mitre.org/data/definitions/610.html
  • CWE list: https://cwe.mitre.org/data/index.html