
Majd Sawaf
A01:2021 Broken Access Control | A02:2021 Cryptographic Failures | A03:2021 Injection | A04:2021 Insecure Design | A05:2021 Security Misconfiguration | A06:2021 Vulnerable and Outdated Components | A07:2021 Identification and Authentication Failures | A08:2021 Software and Data Integrity Failures | A09:2021 Security Logging and Monitoring Failures | A010:2021 Server-Side Request Forgery
Overview
A security flaw that allows unauthorized user access to confidential information.
What It Is
A security vulnerability when a system neglects to enforce access controls based on user privileges, leading to unauthorized users gaining access to information or performing actions they shouldn’t.
Mitigation
Developers should implement strong access controls and least privilege principles. Regular testing, code review are important to remediate access control flaws.
Overview
Inadequate cryptographic systems can lead to unauthorized access to encrypted data when exploited by malicious actors due to implementation or management weaknesses.
What It Is
Inadequate cryptographic systems or protocols that fail to deliver the security they are designed for. When systems fail malicious actors can exploit vulnerabilities to gain unauthorized access to encrypted data, decrypt it and misuse it. These weaknesses can be from improper implementation, poor management practices or other vulnerabilities within the system, allowing for encryption bypass or unauthorized access.
Mitigation
Use strong cryptography, implement secure management practices, ensure secure storage. Utilize reputable cryptographic libraries and frameworks, regular security testing and stay updated on security patches and developments.
Overview
An attacker can inject malicious code into an application to compromise another system.
What It Is
Injection is a type of security flaw that is very well known in application security. It occurs when untrusted data through a query is mishandled which can lead to unintended commands being executed allowing attackers to access authorized information.
They are frequently exploited by attackers to establish a foothold in a system, escalate privileges or take private and confidential information.
Mitigation
Implementing secure code practices
Enforce strict input validation
Regularly updating software
Enhancing least privilege principles
Deploying Web Application Firewall (WAF)
Using secure APIs
Monitoring and logging
Overview
The way developers design programs and integrate security measures. These hidden vulnerabilities can quietly persist in the background making a security risk.
What It Is
A new category for 2021 focusing on design flaw risks. These security vulnerabilities come from inadequate software architecture or design allowing attackers to exploit systems more easily.
Examples of vulnerabilities:
Weak security controls
Insecure APIs
Insufficient monitoring and logging
Unsecured communication
Mitigation
Key Security Practices:
Implementing security measures throughout the software development lifecycle
Implementing strong authentication and access controls
Encrypting sensitive data
Utilizing secure communication protocols
Logging and monitoring system events
Regularly updating and patching software
Overview
Inadequate security configurations makes vulnerabilities and open pathways to attackers. Such vulnerabilities come from misconfigurations that makes the application susceptible to attacks.
What It Is
Poor security configurations of web application components, servers, frameworks and databases can leave systems vulnerable to attacks. When security measures are not appropriately defined, implemented or maintained they expose vulnerabilities for attackers to exploit.
Common Examples:
Weak passwords
Not changing default configurations/settings
Leaving unused features and services enabled
Weak encryption settings
Neglecting data encryption
Insecure storage methods
Failure to apply software patches
Risks associated with public Wi-Fi usage
Social Engineering
Insecure mobile applications
Risks from USB and removable media
Lack of data backups
Mitigation
Stay vigilant against common security threats by employing strong passwords, remaining alert to phishing attempts, maintaining up-to-date software, utilizing VPNs and other tools on public Wi-Fi, implementing data encryption and regularly backing up data. These techniques enhance the security posture and help mitigate risks effectively.
Overview
When code or hardware becomes vulnerable or is no longer maintained.
What It Is
Software that have security flaws because of coding errors, design flaws or outdated libraries or frameworks.
Vulnerable and outdated components pose a threat to web applications.
Attackers can use flaws in vulnerable components to gain unauthorized access.
Operating systems are susceptible to security risks when they lack the latest updates and patches.
Vulnerabilities can come from operating systems, networking equipment, web servers and applications, databases, IoT devices, cloud infrastructure, libraries and frameworks.
Mitigation
Regularly update both software and firmware along with security patches. Security assessments should be made and security practices should be implemented.
Overview
When systems encounter issues in identifying and verifying users, these failures can lead to a variety of security vulnerabilities.
What It Is
Security vulnerabilities in systems responsible for verifying and granting user access.
Common weaknesses:
Easy passwords
Inadequate credentials
Insecure methods of authentication
Deficient MFA
Brute force attacks
Mitigation
Effective password policies
MFA
Restrict number of login attempts
Educate users
Overview
Inadequately secured code and infrastructure vulnerable to integrity infraction, allowing access to applications and data.
What It Is
A new category for 2021. Ensuring the integrity of software and data is important for maintaining the security of web applications. Data integrity ensures that only authorized users can access information. When software systems or data storage lack accuracy and reliability it is because of software bugs, coding errors or hardware failures which can lead to data corruption and unauthorized access.
Mitigation
Implementing a comprehensive data validation strategy to ensure accuracy, prevent injection attacks and deny authorized access alongside strong encryption for data protection, regular security testing, security coding practices, backup and recovery protocols and effective logging and monitoring.
Overview
Web applications that lack real-time monitoring. Security vulnerabilities that come from systems or applications that neglect logging or monitoring security events.
What It Is
Ensuring the logging of login attempts, access control checks and server-side input validation processes.
Poor logging and monitoring creates undetected vulnerabilities in the system. Audits like successful logins, failed logins, password changes and other important changes must be logged to prevent security breaches. Inadequate logging in web applications increases vulnerabilities and makes it hard to detect and respond to threats. Strong logging is important for proactive security.
Mitigation
Implement strong logging
Enable real-time monitoring
Conduct routine log analysis
Incident response plan
Training and awareness
Overview
Server-Side Request Forgery or SSRF is a type of injection attack, a web security vulnerability.
What It Is
A new entry into the OWASP Top 10. SSRF is a web security vulnerability where an attacker deceives the server into making unauthorized requests to internal or external systems. This vulnerability allows attackers to breach internal systems that are isolated from web access. Exploiting SSRF allows attackers to bypass firewalls, gather information within the internal network and pivot to launch attacks on other systems accessible from the compromised server.
Mitigation
Strong input validation
Network segmentation
Proxy utilization
Access controls
Regular security audits