CWE-302: Authentication Bypass by Assumed-Immutable Data
The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.
Browse cwe in architecture and design operation implementation with official CWE context and Glexia analysis.
Search And Filters
Showing 2 of 2 CWE records.
The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.
The product does not properly protect an assumed-immutable element from being modified by an attacker.