Fallos del tipo CWE-1021
215 resultadosImplementação inadequada de requisito de segurança
É quando um desenvolvedor implementa um controle de segurança ou funcionalidade crítica de forma incompleta, incorreta ou desalinhada com a intenção original. O código executa, mas não protege contra a ameaça que deveria, deixando brechas exploráveis.
Ejemplo
Um sistema implementa validação de entrada verificando apenas letras, mas esquece de validar tamanho máximo de string. Um atacante envia um payload gigante que causa buffer overflow apesar da validação existir.
Cómo mitigar
Revise a especificação de segurança contra a implementação real (code review com foco em completude). Use testes de segurança específicos (fuzzing, testes de limite) antes de deploy, não confie que 'parece estar protegido'.
CVE-2022-29911MEDIUMAn improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execuEPSS 0.6%CVE-2022-28286MEDIUMDue to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing atEPSS 0.6%CVE-2023-4956MEDIUMQuay: clickjacking on config-editor page severityEPSS 0.5%CVE-2023-25730MEDIUMA background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode iEPSS 0.5%CVE-2022-3034MEDIUMWhen receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to the remote document EPSS 0.5%CVE-2022-32919MEDIUMThe issue was addressed with improved UI handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Visiting a website tEPSS 0.5%CVE-2024-7404MEDIUMImproper Restriction of Rendered UI Layers or Frames in GitLabEPSS 0.5%CVE-2026-47723HIGHnebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)EPSS 0.5%CVE-2022-20820MEDIUMCisco Webex Meetings Web Interface VulnerabilitiesEPSS 0.5%CVE-2024-7518MEDIUMSelect options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vEPSS 0.5%CVE-2022-20852MEDIUMCisco Webex Meetings Web Interface VulnerabilitiesEPSS 0.5%CVE-2024-2613HIGHData was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulEPSS 0.5%CVE-2024-11700HIGHMalicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approEPSS 0.5%CVE-2024-1890MEDIUMClickjacking vulnerability in Sunny WebboxEPSS 0.5%CVE-2022-46061MEDIUMAeroCMS v0.0.1 is vulnerable to ClickJacking.EPSS 0.5%CVE-2022-43378MEDIUM
A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that
could cause the user to be tricked into peEPSS 0.5%CVE-2023-0057LOWImproper Restriction of Rendered UI Layers or Frames in pyload/pyloadEPSS 0.5%CVE-2022-40268MEDIUMImproper Restriction of Rendered UI Layers or Frames vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.EPSS 0.5%CVE-2024-3911MEDIUMWelotec: Clickjacking Vulnerability in WebUIEPSS 0.5%CVE-2023-5103MEDIUMImproper Restriction of Rendered UI Layers or Frames in RDT400 in SICK APU allows an unprivileged remote attacker to potentially reveal sensEPSS 0.5%