Information Leak Through Environmental Variables
Weakness ID: 526 (Weakness Variant)Status: Incomplete
+ Description

Description Summary

Environmental variables may contain sensitive information about a remote server.
+ Time of Introduction
  • Architecture and Design
  • Implementation
  • Operation
+ Potential Mitigations

Protect information stored in environment variable from being exposed to the user.

+ Relationships
NatureTypeIDNameView(s) this relationship pertains toView(s)
ChildOfWeakness ClassWeakness Class200Information Exposure
Development Concepts (primary)699
Research Concepts (primary)1000
ChildOfCategoryCategory731OWASP Top Ten 2004 Category A10 - Insecure Configuration Management
Weaknesses in OWASP Top Ten (2004) (primary)711
+ Content History
Modifications
Modification DateModifierOrganizationSource
2008-07-01Eric DalciCigitalExternal
updated Potential Mitigations, Time of Introduction
2008-09-08CWE Content TeamMITREInternal
updated Relationships
2009-03-10CWE Content TeamMITREInternal
updated Relationships