|
Status: Incomplete Weakness ID: 525 (Weakness Variant)Description Summary For each web page, the application should have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. Potential Mitigations Protect information stored in cache. Do not store unnecessarily sensitive information in the cache. Consider using encryption in the cache. Other Notes You should use a restrictive caching policy for forms and web pages that potentially contain sensitive information. The risk is that this information could be stored in a client-side cache (with most browsers) and left behind for other users to find. The most severe risk is for applications where the intended access is from public terminals, such as those in libraries and Internet cafes. Relationships
Taxonomy Mappings
Time of Introduction ImplementationRelated Attack Patterns
Content History Submissions Anonymous Tool Vendor (under NDA). (Externally Mined) Modifications Eric Dalci. Cigital. 2008-07-01. (External) updated Potential_Mitigations, Time_of_Introduction CWE Content Team. MITRE. 2008-09-08. (Internal) updated Relationships, Other_Notes, Taxonomy_Mappings |
|
|
|||