Umbra Wiki weakness weakness/CWE-767
Back to wiki

CWE-767 — Access to Critical Private Variable via Public Method

provenance: imported · CWE: CWE-767

CWE-767: Access to Critical Private Variable via Public Method

MITRE CWE weakness

Kind Weakness
Abstraction Base
Status Incomplete
Likelihood of exploit

Description

The product defines a public method that reads or modifies a private variable.

If an attacker modifies the variable to contain unexpected values, this could violate assumptions from other parts of the code. Additionally, if an attacker can read the private variable, it may expose sensitive information or make it easier to launch further attacks.

Common consequences

  • Integrity, Other: Modify Application Data, Other

Mitigations

Implementation — Use class accessor and mutator methods appropriately. Perform validation when accepting data from a public method that is intended to modify a critical private variable. Also be sure that appropriate access controls are being applied when a public method interfaces with critical data.

References

  • CWE page: https://cwe.mitre.org/data/definitions/767.html
  • CWE list: https://cwe.mitre.org/data/index.html