Skip to content

ES2604-20e90224 - CWE-391 Mapping Notes - Remove Prohibited Suggestion #186

@stevechristeycoley

Description

@stevechristeycoley

Submission File: ES2604-20e90224-mod-CWE-391-mapping-notes-suggestion.txt

ID: ES2604-20e90224

SUBMISSION DATE: 2026-04-07 09:26:57

NAME: CWE-391 Mapping Notes - Remove Prohibited Suggestion

DESCRIPTION:

CWE-391 (Unchecked Error Condition) lists CWE-1069 (Empty Exception Block)
as a Mapping_Notes <Suggestion>, but CWE-1069 is itself marked
<Usage>Prohibited</Usage>.

This creates a contradiction: analysts following CWE-391's mapping guidance
are directed to a CWE that they are also prohibited from using.

Remove CWE-1069 from CWE-391's <Suggestions> list and from the <Comments>
text. The remaining suggestions (CWE-252 and CWE-248) are both Allowed and
provide adequate coverage.

Metadata

Metadata

Assignees

No one assigned

    Labels

    External-SubmissionPhase02-Ack-ReceiptThe CWE team has acknowledged receipt of the submission by notifying the submitter

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions