Modes d'introduction
Architecture and Design
Implementation : REALIZATION: This weakness is caused during implementation of an architectural security tactic.
            Plateformes applicables
Langue
Class: Not Language-Specific (Undetermined)            
            Conséquences courantes
            
            
            
            
                | Portée | Impact | Probabilité | 
            
            
| Integrity Confidentiality
 Availability
 | Execute Unauthorized Code or Commands 
 Note: Execution of arbitrary code in the context of usage of the resources with dangerous names.
 |  | 
| Confidentiality Availability
 | Read Application Data, DoS: Crash, Exit, or Restart 
 Note: Crash of the consumer code of these resources resulting in information leakage or denial of service.
 |  | 
                    
                
             
            
Mesures d’atténuation potentielles
Phases : Architecture and Design
Do not allow users to control names of resources used on the server side.
Phases : Architecture and Design
Perform allowlist input validation at entry points and also before consuming the resources. Reject bad file names rather than trying to cleanse them.
Phases : Architecture and Design
Make sure that technologies consuming the resources are not vulnerable (e.g. buffer overflow, format string, etc.) in a way that would allow code execution if the name of the resource is malformed.
            Notes de cartographie des vulnérabilités
            Justification : This CWE entry is at the Base level of abstraction, which is a preferred level of abstraction for mapping to the root causes of vulnerabilities.            
            
Commentaire : Carefully read both the name and description to ensure that this mapping is an appropriate fit. Do not try to 'force' a mapping to a lower-level Base/Variant simply to comply with this preferred level of abstraction.            
            Soumission
            
                
                    
                    
                        | Nom | Organisation | Date | Date de publication | Version | 
                    
                    
                    
                        | Evgeny Lebanidze | Cigital | 2008-01-30 +00:00 | 2008-01-30 +00:00 | Draft 8 | 
                    
                
             
            
            Modifications
            
                
                    
                    
                        | Nom | Organisation | Date | Commentaire | 
                    
                    
                        
                            | CWE Content Team | MITRE | 2008-09-08 +00:00 | updated Common_Consequences, Relationships | 
                        
                            | CWE Content Team | MITRE | 2008-10-14 +00:00 | updated Description | 
                        
                            | CWE Content Team | MITRE | 2009-10-29 +00:00 | updated Common_Consequences | 
                        
                            | CWE Content Team | MITRE | 2010-06-21 +00:00 | updated Description, Name, Type | 
                        
                            | CWE Content Team | MITRE | 2010-12-13 +00:00 | updated Common_Consequences | 
                        
                            | CWE Content Team | MITRE | 2011-06-01 +00:00 | updated Common_Consequences | 
                        
                            | CWE Content Team | MITRE | 2012-05-11 +00:00 | updated Observed_Examples, Relationships | 
                        
                            | CWE Content Team | MITRE | 2012-10-30 +00:00 | updated Potential_Mitigations | 
                        
                            | CWE Content Team | MITRE | 2014-07-30 +00:00 | updated Relationships, Taxonomy_Mappings | 
                        
                            | CWE Content Team | MITRE | 2017-05-03 +00:00 | updated Potential_Mitigations | 
                        
                            | CWE Content Team | MITRE | 2017-11-08 +00:00 | updated Applicable_Platforms, Description, Enabling_Factors_for_Exploitation, Modes_of_Introduction, Relationships | 
                        
                            | CWE Content Team | MITRE | 2020-02-24 +00:00 | updated Relationships | 
                        
                            | CWE Content Team | MITRE | 2020-06-25 +00:00 | updated Potential_Mitigations, Relationships | 
                        
                            | CWE Content Team | MITRE | 2023-01-31 +00:00 | updated Description | 
                        
                            | CWE Content Team | MITRE | 2023-04-27 +00:00 | updated Relationships | 
                        
                            | CWE Content Team | MITRE | 2023-06-29 +00:00 | updated Mapping_Notes |