CWE-20: Improper Input Validation

CWE-20 là gì?

MITRE CWE

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Xác minh để phân tích mục CWE này

Bước xác minh ngắn giúp bảo vệ nguồn dữ liệu chính thức và hạn chế việc gọi AI tự động.

Định nghĩa MITRE gốc (tiếng Anh)

MITRE CWE

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Input validation is a frequently-used technique for checking potentially dangerous inputs in order to ensure that the inputs are safe for processing within the code, or when communicating with other components. Input can consist of: - raw data - strings, numbers, parameters, file contents, etc. - metadata - information about the raw data, such as headers or size Data can be simple or structured. Structured data can be composed of many nested layers, composed of combinations of metadata and raw data, with other simple or structured data. Many properties of raw data or metadata may need to be validated upon entry into the code, such as: - specified quantities such as size, length, frequency, price, rate, number of operations, time, etc. - implied or derived quantities, such as the actual size of a file instead of a specified size - indexes, offsets, or positions into more complex data structures - symbolic keys or other elements into hash tables, associative arrays, etc. - well-formedness, i.e. syntactic correctness - compliance with expected syntax - lexical token correctness - compliance with rules for what is treated as a token - specified or derived type - the actual type of the input (or what the input appears to be) - consistency - between individual data elements, between raw data and metadata, between references, etc. - conformance to domain-specific rules, e.g. business logic - equivalence - ensuring that equivalent inputs are treated the same - authenticity, ownership, or other attestations about the input, e.g. a cryptographic signature to prove the source of the data Implied or derived properties of data must often be calculated or inferred by the code itself. Errors in deriving properties may be considered a contributing factor to improper input validation.

Mô tả chi tiết

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.

Đặc điểm

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.

Giai đoạn hình thành

  • Kiến trúc và thiết kế
  • Hiện thực hóa

Tác động thường gặp

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.
  • Tính sẵn sàng

    Từ chối dịch vụ: sập, thoát hoặc khởi động lại, Từ chối dịch vụ: tiêu thụ tài nguyên CPU, Từ chối dịch vụ: tiêu thụ bộ nhớ

  • Tính bí mật

    Đọc bộ nhớ, Đọc tệp hoặc thư mục

  • Tính toàn vẹn, Tính bí mật, Tính sẵn sàng

    Thay đổi bộ nhớ, Thực thi mã hoặc lệnh trái phép

Biện pháp giảm thiểu

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.
  • Kiến trúc và thiết kế · Giảm bề mặt tấn công
  • Kiến trúc và thiết kế · Thư viện hoặc framework
  • Kiến trúc và thiết kế, Hiện thực hóa · Giảm bề mặt tấn công
  • Hiện thực hóa · Kiểm tra dữ liệu đầu vàoHiệu quả: Cao
  • Kiến trúc và thiết kế
  • Hiện thực hóa
  • Hiện thực hóa
  • Hiện thực hóa
  • Hiện thực hóa
  • Hiện thực hóa

Phương pháp phát hiện

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.
  • Phân tích tĩnh tự động
  • Phân tích tĩnh thủ công
  • Kiểm thử fuzzing
  • Phân tích tĩnh tệp nhị phân hoặc bytecode tự độngHiệu quả: SOAR một phần
  • Phân tích tĩnh tệp nhị phân hoặc bytecode thủ côngHiệu quả: SOAR một phần
  • Phân tích động với diễn giải kết quả tự độngHiệu quả: Cao
  • Phân tích động với diễn giải kết quả thủ côngHiệu quả: Cao
  • Phân tích tĩnh mã nguồn thủ côngHiệu quả: Cao
  • Phân tích tĩnh mã nguồn tự độngHiệu quả: Cao
  • Rà soát kiến trúc hoặc thiết kếHiệu quả: Cao

Lỗ hổng điển hình

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.

Nguồn và tài liệu tham khảo

Tham chiếu

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Tìm hiểu thêm

Kiểm tra chuyên sâu cùng giải pháp quản lý rủi ro Web toàn diện

Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.

Khám phá CyStack VulnScan
CyStack VulnScan dashboard