CWE-1268: Policy Privileges are not Assigned Consistently Between Control and Data Agents
概要
CWE-1268(Policy Privileges are not Assigned Consistently Between Control and Data Agents)は各種脆弱性データベースや評価で用いられる弱点タイプを説明します。定義・背景・対応する CVE は以下の各セクションを参照してください。
The product's hardware-enforced access control for a particular resource improperly accounts for privilege discrepancies between control and write policies.
Insufficient policy enforcement in PWAs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to install a PWA without user consent via a crafted H…
旧名称
Agents Included in Control Policy are not Contained in Less-Privileged Policy(2020-08-20)