A new minor release of CWE (version 2.11) is now posted on the website. This version continued with the reorganization of the Development Concepts View (CWE-699), specifically related to the relationship of CWE-20 (Improper Input Validation) and other traversal, injection, and overflow type weaknesses. These are now set as CanPrecede/CanFollow relationships instead of parent/child relationships.
A number of smaller items were also addressed including fixes to some demonstrative examples, summaries, and related attack patterns.
Two weaknesses were deprecated with this release as both were redundant concepts that are covered by other existing weaknesses.
CWE-545: Use of Dynamic Class Loading
CWE-592: Authentication Bypass Issues
A full description of the changes can be found in the detailed different report.