CWE-675: Multiple Operations on Resource in Single-Operation Context
CWE版本: 4.18
更新日期: 2025-09-09
弱点描述
The product performs the same operation on a resource two or more times, when the operation should only be applied once.
常见后果
影响范围: Other
技术影响: Other
观察示例
参考: CVE-2009-0935
Attacker provides invalid address to a memory-reading function, causing a mutex to be unlocked twice
参考: CVE-2019-13351
file descriptor double close can cause the wrong file to be associated with a file descriptor.
参考: CVE-2004-1939
XSS protection mechanism attempts to remove "/" that could be used to close tags, but it can be bypassed using double encoded slashes (%252F)
引入模式
| 阶段 | 说明 |
|---|---|
| Implementation | - |