COMMON WEAKNESS ENUMERATIONIncomplete

CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Abstraction

Class

Structure

Simple

Likelihood of Exploit

High

Understand the problem

What is the problem?

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Root cause

How and when does the problem arise?

Lifecycle phase

Implementation

REALIZATION: This weakness is caused during implementation of an architectural security tactic.

Risk

What does successful exploitation lead to?

Read Application Data

Affected security scopes: Confidentiality

Many injection attacks involve the disclosure of important information -- in terms of both data sensitivity and usefulness in further exploitation.
Bypass Protection Mechanism

Affected security scopes: Access Control

In some cases, injectable code controls authentication; this may lead to a remote vulnerability.
Alter Execution Logic

Affected security scopes: Other

Injection attacks are characterized by the ability to significantly change the flow of a given process, and in some cases, to the execution of arbitrary code.
Other

Affected security scopes: Integrity, Other

Data injection attacks lead to loss of data integrity in nearly all cases as the control-plane data injected is always incidental to data recall or writing.
Hide Activities

Affected security scopes: Non-Repudiation

Often the actions performed by injected control code are unlogged.

Defence

How is it prevented and fixed?

Requirements

Security requirement

Detail
Programming languages and supporting technologies might be chosen which are not subject to these issues.

Implementation

Implementation-phase defence

Detail
Utilize an appropriate mix of allowlist and denylist parsing to filter control-plane syntax from all input.

Verification

How is it detected?

Automated Static Analysis

High
Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

MITRE diagram

Weakness relationships and flow

CWE-74 MITRE diagramı