CWE-345: Insufficient Verification of Data Authenticity
Insufficient Verification of Data Authenticity
Weakness ID: 345 (Weakness Class) Status: Draft
Description
Description Summary
The software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Time of Introduction
Architecture and Design
Implementation
Common Consequences
Scope Effect
Integrity
Other
Technical Impact: Varies by context; Unexpected state
Relationships
Relationship Notes
"origin validation" could fall under this.
Taxonomy Mappings
Mapped Taxonomy Name Node ID Fit Mapped Node Name
PLOVER Insufficient Verification of Data
OWASP Top Ten 2004 A3 CWE_More_Specific Broken Authentication and Session
Management
WASC 12 Content Spoofing
References
[REF-17] Michael Howard, David LeBlanc
and John Viega. "24 Deadly Sins of Software Security". "Sin 15: Not Updating Easily." Page 231. McGraw-Hill. 2010.
Maintenance Notes
The specific ways in which the origin is not properly identified should be
laid out as separate weaknesses. In some sense, this is more like a
category.
Content History
Submissions Submission Date Submitter Organization Source PLOVER Externally Mined Modifications Modification Date Modifier Organization Source 2008-07-01 Eric Dalci Cigital External updated Time_of_Introduction 2008-09-08 CWE Content Team MITRE Internal updated Maintenance_Notes, Relationships,
Relationship_Notes, Taxonomy_Mappings 2009-05-27 CWE Content Team MITRE Internal updated Related_Attack_Patterns 2009-07-27 CWE Content Team MITRE Internal updated Related_Attack_Patterns 2010-02-16 CWE Content Team MITRE Internal updated Taxonomy_Mappings 2010-04-05 CWE Content Team MITRE Internal updated Related_Attack_Patterns 2010-12-13 CWE Content Team MITRE Internal updated Related_Attack_Patterns 2011-06-01 CWE Content Team MITRE Internal updated Common_Consequences 2011-06-27 CWE Content Team MITRE Internal updated Common_Consequences 2012-05-11 CWE Content Team MITRE Internal updated References, Related_Attack_Patterns,
Relationships Previous Entry Names Change Date Previous Entry
Name 2008-04-11 Insufficient Verification of
Data