Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

Authentication Bypass By Alternate Name High

Assigning the same variable from different untrusted sources like request parameters, session data, etc. in Go code can cause confused logic and vulnerabilities. The variable may end up with an unintended blended value from overlapping disjoint sources. To avoid inconsistent state and logic issues, variables should be assigned from a single trusted authoritative source. Consolidating assignment to one clear source of truth ensures code operates on the intended value, avoiding blended state from multiple unvalidated sources.

Detector ID
go/authentication-bypass-by-alternate-name@v1.0
Category
Common Weakness Enumeration (CWE) external icon
Tags
-