CWE-214

Overview
  • CWE ID
  • 214
  • CWE Name
  • Invocation of Process Using Visible Sensitive Information
  • CWE Abstraction
  • Base
  • CWE structure
  • Simple
  • CWE Status
  • Incomplete
Description
A process is invoked with sensitive command-line arguments, environment variables, or other elements that can be seen by other processes on the operating system.
Extended Description
Many operating systems allow a user to list information about processes that are owned by other users. Other users could see information such as command line arguments or environment variable settings. When this data contains sensitive information such as
Related CWEs
CWE ID View ID Nature Ordinal
497 1000 ChildOf Primary