Home / Vulnerability Database / Kotlin : Undocumented feature: security parameters modification
Kotlin

Kotlin : Undocumented feature: security parameters modification

Classification

OWASP ASVS
CWE/SANS Top 25 2011
CWE/SANS Top 25 2021

Overview

The application contains the code that changes the logic of authentication by overwriting the variable that indicates whether the authentication is successful.

Using the assignment operator (=) instead of the comparison operator (==) is a common mistake. It is particularly dangerous and may be the part of the backdoor when occurs in the methods related to authentication.

LOW

DerScanner Severity Score

Do you want to fix Kotlin : Undocumented feature: security parameters modification in your application?

See also

Kotlin

Kotlin : Missing required cryptographic step

Kotlin

Kotlin : Logging into system output

Kotlin

Kotlin : Call of notify() in synchronized block