Category-264: 权限、特权和访问控制

ID: 264 Status: Incomplete

Summary

Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Membership

ID NAME
CWE-265 权限/沙箱问题
CWE-275 Permission Issues
CWE-282 属主管理不恰当
CWE-284 访问控制不恰当
CWE-749 暴露危险的方法或函数

Taxonomy Mappings

Mapped Taxonomy Name Node ID Fit Mapped Node Name
PLOVER Permissions, Privileges, and ACLs

References

REF-7 Writing Secure Code