Not Using Password Aging - (262)
https://cwe.mitre.org/data/definitions/262.html

Password Aging with Long Expiration - (263)
https://cwe.mitre.org/data/definitions/263.html

REFERENCES needs updating with:

https://pages.nist.gov/800-63-3/sp800-63b.html

5.1.1.2 Memorized Secret Verifiers

Verifiers SHOULD NOT impose other composition rules (e.g., requiring
mixtures of different character types or prohibiting consecutively repeated
characters) for memorized secrets. Verifiers SHOULD NOT require memorized
secrets to be changed arbitrarily (e.g., periodically). However, verifiers
SHALL force a change if there is evidence of compromise of the
authenticator.

And ideally, we should rewrite BOTH of these CWE's to state "these are
retired/wrong"

--
Kurt Seifried (He/Him)
k...@seifried.org

Reply via email to