Trusting External Input

Kind: anti-pattern

Layer: Security Core

Record: lexicon:trusting-external-input

Canonical: Lexicon

Accepting external input as well-formed and safe without validating it, exposing the system to malformed or malicious data.

Listed in Lexicon terms, after Trusted Internal Network Assumption and before Unbounded Autonomy.

Category

Violates

Negated by

Linked from