The product omits a break statement within a switch or similar construct, causing code associated with multiple conditions to execute. This can cause problems when the programmer only intended to execute code associated with one condition.
Omitting a break statement so that one may fall through is often indistinguishable from an error, and therefore should be avoided. If you need to use fall-through capabilities, make sure that you have clearly documented this within the switch statement, and ensure that you have examined all the logical possibilities.
The functionality of omitting a break statement could be clarified with an if statement. This method is much safer.
Our security experts can help you identify and remediate CWE-484 vulnerabilities in your codebase.
Get Security Assessment