Falhas do tipo CWE-1021

215 resultados

Implementação inadequada de mecanismo de segurança

A lógica de segurança foi implementada de forma incompleta ou incorreta, deixando brechas que um atacante pode explorar. É quando o desenvolvedor tenta fazer o certo (validar entrada, criptografar dados, autenticar usuário), mas comete erros na execução que anulam a proteção.

Exemplo

Um sistema implementa autenticação de dois fatores, mas aceita o código OTP mesmo depois de expirado; ou valida se um arquivo é imagem checando apenas a extensão, não o conteúdo real do arquivo.

Como mitigar

Revise a implementação de controles de segurança críticos (autenticação, validação, criptografia) com code review rigoroso e testes de segurança específicos. Use bibliotecas consolidadas em vez de reinventar mecanismos; nunca implemente criptografia ou lógica sensível do zero sem expertise comprovada.

CVE-2022-29911MEDIUMAn improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execuEPSS 0.6%CVE-2022-28286MEDIUMDue to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing atEPSS 0.6%CVE-2023-4956MEDIUMQuay: clickjacking on config-editor page severityEPSS 0.5%CVE-2023-25730MEDIUMA background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode iEPSS 0.5%CVE-2022-3034MEDIUMWhen receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to the remote document EPSS 0.5%CVE-2022-32919MEDIUMThe issue was addressed with improved UI handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Visiting a website tEPSS 0.5%CVE-2024-7404MEDIUMImproper Restriction of Rendered UI Layers or Frames in GitLabEPSS 0.5%CVE-2026-47723HIGHnebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)EPSS 0.5%CVE-2022-20820MEDIUMCisco Webex Meetings Web Interface VulnerabilitiesEPSS 0.5%CVE-2024-7518MEDIUMSelect options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vEPSS 0.5%CVE-2022-20852MEDIUMCisco Webex Meetings Web Interface VulnerabilitiesEPSS 0.5%CVE-2024-2613HIGHData was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulEPSS 0.5%CVE-2024-11700HIGHMalicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approEPSS 0.5%CVE-2024-1890MEDIUMClickjacking vulnerability in Sunny WebboxEPSS 0.5%CVE-2022-46061MEDIUMAeroCMS v0.0.1 is vulnerable to ClickJacking.EPSS 0.5%CVE-2022-43378MEDIUM A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause the user to be tricked into peEPSS 0.5%CVE-2023-0057LOWImproper Restriction of Rendered UI Layers or Frames in pyload/pyloadEPSS 0.5%CVE-2022-40268MEDIUMImproper Restriction of Rendered UI Layers or Frames vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.EPSS 0.5%CVE-2024-3911MEDIUMWelotec: Clickjacking Vulnerability in WebUIEPSS 0.5%CVE-2023-5103MEDIUMImproper Restriction of Rendered UI Layers or Frames in RDT400 in SICK APU allows an unprivileged remote attacker to potentially reveal sensEPSS 0.5%