SCWE-021: Unsecured Data Transmission
Stable Version v1.0
This content is in the version-(v1.0) and still under active development, so it is subject to change any time (e.g. structure, IDs, content, URLs, etc.).
Relationships¶
- CWE-319: Cleartext Transmission of Sensitive Information
CWE-319 Link
Description¶
Unsecured data transmission refers to the transmission of sensitive information, such as private keys or user data, without encryption. This can lead to: - Interception of sensitive data by malicious actors. - Exploitation of vulnerabilities in the contract. - Loss of funds or data.
Remediation¶
- Use encryption: Encrypt sensitive data before transmission.
- Leverage secure protocols: Use HTTPS or other secure communication protocols.
- Avoid transmitting sensitive data: Minimize the transmission of sensitive data whenever possible.
Examples¶
-
Unsecured Data Transmission
-
Secured Data Transmission