Weaknesses of type CWE-1021

216 results

Implementação inadequada de mecanismo de segurança

Ocorre quando um desenvolvedor implementa um controle de segurança (autenticação, criptografia, validação, etc.) de forma incorreta ou incompleta, deixando brechas no mecanismo pretendido. A lógica pode estar presente, mas falha na prática porque não cobre todos os casos, usa configurações fracas ou não segue padrões estabelecidos.

Example

Uma aplicação implementa autenticação de dois fatores, mas aceita qualquer código OTP com mais de 4 dígitos sem validar se é realmente o esperado; ou usa MD5 para hash de senhas porque 'é rápido'. O mecanismo existe, mas não funciona corretamente.

How to mitigate

Use bibliotecas e frameworks de segurança consolidados em vez de reinventar a roda; revise implementações críticas (auth, crypto, validação) contra padrões da indústria (OWASP, NIST); execute testes de segurança específicos e code review com foco em lógica de controles, não apenas sintaxe.

CVE-2022-29911MEDIUMAn improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execuEPSS 0.6%CVE-2022-28286MEDIUMDue to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing atEPSS 0.6%CVE-2023-4956MEDIUMQuay: clickjacking on config-editor page severityEPSS 0.5%CVE-2023-25730MEDIUMA background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode iEPSS 0.5%CVE-2022-3034MEDIUMWhen receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to the remote document EPSS 0.5%CVE-2022-32919MEDIUMThe issue was addressed with improved UI handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Visiting a website tEPSS 0.5%CVE-2024-7404MEDIUMImproper Restriction of Rendered UI Layers or Frames in GitLabEPSS 0.5%CVE-2026-47723HIGHnebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)EPSS 0.5%CVE-2022-20820MEDIUMCisco Webex Meetings Web Interface VulnerabilitiesEPSS 0.5%CVE-2024-7518MEDIUMSelect options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vEPSS 0.5%CVE-2022-20852MEDIUMCisco Webex Meetings Web Interface VulnerabilitiesEPSS 0.5%CVE-2024-2613HIGHData was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulEPSS 0.5%CVE-2024-11700HIGHMalicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approEPSS 0.5%CVE-2024-1890MEDIUMClickjacking vulnerability in Sunny WebboxEPSS 0.5%CVE-2022-46061MEDIUMAeroCMS v0.0.1 is vulnerable to ClickJacking.EPSS 0.5%CVE-2022-43378MEDIUM A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause the user to be tricked into peEPSS 0.5%CVE-2023-0057LOWImproper Restriction of Rendered UI Layers or Frames in pyload/pyloadEPSS 0.5%CVE-2022-40268MEDIUMImproper Restriction of Rendered UI Layers or Frames vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.EPSS 0.5%CVE-2024-3911MEDIUMWelotec: Clickjacking Vulnerability in WebUIEPSS 0.5%CVE-2023-5103MEDIUMImproper Restriction of Rendered UI Layers or Frames in RDT400 in SICK APU allows an unprivileged remote attacker to potentially reveal sensEPSS 0.5%