CWE-421: Race Condition During Access to Alternate Channel
BaseDraft
The product opens an alternate channel to communicate with an authorized user, but the channel is accessible to other actors.
View on MITREBack to CWE Lookup
Extended Description
This creates a race condition that allows an attacker to access the channel before the authorized user does.
Technical Details
- Structure
- Simple
Applicable To
Not Language-Specific