|
|
|
|
CWE-526: Information Exposure Through Environmental Variables
| | Information Exposure Through Environmental Variables |
|
| Weakness ID: 526 (Weakness Variant) | | Status: Incomplete |
Description
Description Summary Environmental variables may contain sensitive information about a remote server.
Time of Introduction
- Architecture and Design
- Implementation
- Operation
Common Consequences | Scope | Effect |
Confidentiality | Technical Impact: Read application
data |
Potential Mitigations
Phase: Architecture and Design Protect information stored in environment variable from being exposed
to the user. |
Relationships Content History | Modifications |
|---|
| Modification Date | Modifier | Organization | Source |
|---|
| 2008-07-01 | Eric Dalci | Cigital | External | | updated Potential_Mitigations,
Time_of_Introduction | | 2008-09-08 | CWE Content Team | MITRE | Internal | | updated Relationships | | 2009-03-10 | CWE Content Team | MITRE | Internal | | updated Relationships | | 2011-03-29 | CWE Content Team | MITRE | Internal | | updated Name | | 2011-06-01 | CWE Content Team | MITRE | Internal | | updated Common_Consequences, Relationships,
Taxonomy_Mappings | | 2012-05-11 | CWE Content Team | MITRE | Internal | | updated Relationships,
Taxonomy_Mappings | | 2012-10-30 | CWE Content Team | MITRE | Internal | | updated Potential_Mitigations | | Previous Entry Names |
|---|
| Change Date | Previous Entry
Name |
|---|
| 2011-03-29 | Information Leak Through
Environmental Variables | |
|