This page is experimental and may change significantly in future releases.
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
Properties
id: d3f:CWE-551
- name
- Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
- definition
- If a web server does not fully parse requested URLs before it examines them for authorization, it may be possible for an attacker to bypass authorization protection.
Neighbors
CWE-551 has no direct neighbors in this release.Inferred Relationships
Related Countermeasure Techniques
Related Weaknesses
CWE-551 has no related weaknesses in this release.