CWE-183: Permissive Whitelist
Weakness ID: 183 (Weakness Base) Status: Draft
Description
Description Summary
An application uses a "whitelist" of acceptable values, but the whitelist includes at least one unsafe value, leading to resultant weaknesses .
Time of Introduction
Common Consequences
Scope Effect
Access Control
Technical Impact: Bypass protection
mechanism
Weakness Ordinalities
Ordinality Description
Primary
(where
the weakness exists independent of other weaknesses)
Relationships
Taxonomy Mappings
Mapped Taxonomy Name Node ID Fit Mapped Node Name
PLOVER Permissive Whitelist
References
[REF-7] Mark Dowd, John McDonald
and Justin Schuh. "The Art of Software Security Assessment". Chapter 8, "Eliminating Metacharacters", Page
435.. 1st Edition. Addison Wesley. 2006.
Content History
Submissions Submission Date Submitter Organization Source PLOVER Externally Mined Modifications Modification Date Modifier Organization Source 2008-07-01 Eric Dalci Cigital External updated Potential_Mitigations,
Time_of_Introduction 2008-09-08 CWE Content Team MITRE Internal updated Description, Relationships, Taxonomy_Mappings,
Weakness_Ordinalities 2009-03-10 CWE Content Team MITRE Internal updated Relationships 2009-07-27 CWE Content Team MITRE Internal updated Potential_Mitigations 2010-02-16 CWE Content Team MITRE Internal updated Relationships 2011-03-29 CWE Content Team MITRE Internal updated Potential_Mitigations 2011-06-01 CWE Content Team MITRE Internal updated Common_Consequences 2012-05-11 CWE Content Team MITRE Internal updated References, Relationships 2013-02-21 CWE Content Team MITRE Internal updated Potential_Mitigations