Detect Missing Critical Step in Authentication with Automated Static Analysis
Documented detection approaches include Automated Static Analysis; recorded impacts include Bypass Protection Mechanism, Gain Privileges or Assume Identity, Read Application Data, and Execute Unauthorized Code or Commands; observed examples include CVE-2004-2163, and CVE-2005-3327. Use these source-defined anchors to turn CWE-304 into implementation, review, and verification checks for the affected component.
CWE-304: Missing Critical Step in Authentication — MITRE CWE