CWE-1038 不安全的自动优化

Insecure Automated Optimizations

结构: Simple

Abstraction: Class

状态: Draft

被利用可能性: Low


The product uses a mechanism that automatically optimizes code, e.g. to improve a characteristic such as performance, but the optimizations can have an unintended side effect that might violate an intended security assumption.


范围 影响 注释
Integrity Alter Execution Logic The optimizations alter the order of execution resulting in side effects that were not intended by the original developer.