3. of Information Disclosure I
An attacker can see error messages with security-sensitive content.
Threat |
|
The system will tell the attacker whether the username is incorrect, or the password is incorrect. So, the attacker will know they have found a valid user. |
|
CAPEC |
CAPEC-112 - Brute Force CAPEC-575 - Account Fingerprinting CAPEC-70 - Try Common or Default Usernames and Passwords CAPEC-565 - Password Spraying |
ASVS |
7.4.1 - Ensure error messages don’t leak security-sensitive information to the user. |
CWE |
CWE-209 - Generation of Error Messages Containing Sensitive Information CWE-210 - Self-Generated Error Message Containing Sensitive Information |