ã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãª (cross-site request forgery) ã¯ãWebã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ã®ä¸ã¤[1]ãããã¯ãããå©ç¨ããæ»æãç¥ç§°ã¯CSRFï¼ã·ã¼ãµã¼ã (sea-surf) ã¨èªã¾ããäºããã[2][3]ï¼ãã¾ãã¯XSRFããªã¯ã¨ã¹ãå¼·è¦[4]ãã»ãã·ã§ã³ã©ã¤ãã£ã³ã° (session riding[3]) ã¨ãå¼ã°ããã1990年代ã¯ã¤ã¡ã¿ã°æ»æã¨ãå¼ã°ãã¦ãã[è¦åºå ¸]ãèå¼±æ§ãããªã¼åã«åé¡ããCWEã§ã¯CSRFããã¼ã¿èªè¨¼ã®ä¸ååãªæ¤è¨¼ (CWE-345) ã«ããèå¼±æ§ã®ã²ã¨ã¤ã¨ãã¦åé¡ãã¦ãã (CWE-352)[5]ã ãªãCSRFã®æ£å¼å称ã¯ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã° (XSS) ã¨ä¼¼ã¦ããããXSSã¯ä¸é©åãªå ¥åç¢ºèª (CWE-20) ã«ããã¤ã³ã¸ã§ã¯ã·ã§ã³ (CWE-74) ã®ã²ã¨ã¤ã¨ãã¦åé¡ããã¦ãã[5]ãå ¨ãç°ãªã種é¡ã®
{{#tags}}- {{label}}
{{/tags}}