CompoundDraft
CWE-689Permission Race Condition During Resource Copy
Category: authz
Description
The product, while copying or cloning a resource, does not set the resource's permissions or access control until the copy is complete, leaving the resource exposed to other spheres while the copy is taking place.
Common consequences· 1
- Confidentiality / Integrity — Read Application Data, Modify Application Data
Related CAPEC attack patterns· 2
References
Exploits (incoming)2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Leveraging Race Conditionscapec-26 | 100% | live |
| AttackPattern | Leveraging Race Conditions via Symbolic Linkscapec-27 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.