CWE-270 - Privilege Context Switching Error
- 摘要:Base
- 结构:Simple
- 状态:Draft
- 发布日期:2006-07-19
- 更新日期:2025-12-11
名称
Privilege Context Switching Error
描述
The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.
常见后果
范围:Access Control
影响:Gain Privileges or Assume Identity
注释:A user can assume the identity of another user with separate privileges in another context. This will give the user unauthorized access that may allow them to acquire the access information of other users.