CVEbaza.plSłownik CWECWE-1021
Common Weakness Enumeration

CWE-1021

Improper Restriction of Rendered UI Layers or Frames

Kategoria: BaseCVE: 482
Opis

Aplikacja internetowa nie ogranicza lub nieprawidłowo ogranicza obiekty ramek lub warstwy interfejsu użytkownika należące do innej aplikacji lub domeny. Może to prowadzić do utraty kontroli nad tym, jakie elementy użytkownik widzi i z którymi może wchodzić w interakcję.

Description (EN)

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

Podatności CVE z CWE-1021 (482)
9.8
CVSS
CRITICAL
CVE-2021-43048

Komponenty Interior Server i Gateway Server w TIBCO PartnerExpress zawierają podatność umożliwiającą przeprowadzenie ataku clickjacking przez nieuwierzytelnionego atakującego z dostępem sieciowym. Podatność jest oceniana jako krytyczna (CVSS 9.8), co może wskazywać na poważne konsekwencje dla poufności, integralności i dostępności systemu.

pub. 2021-11-16
9.8
CVSS
CRITICAL
CVE-2021-23274

Komponent Config UI w produktach TIBCO API Exchange Gateway oraz TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric zawiera podatność umożliwiającą przeprowadzenie ataku clickjacking przez nieuwierzytelnionego atakującego z dostępem sieciowym. Podatność sklasyfikowano jako krytyczną (CVSS 9.8), choć mechanizm clickjackingu jest tu szczególnie niepokojący ze względu na brak wymagania interakcji innych użytkowników.

pub. 2021-03-23
9.8
CVSS
CRITICAL
CVE-2016-2496

Podatność w implementacji okna dialogowego uprawnień (Framework UI) w systemie Android 6.x pozwala atakującym na przeprowadzenie ataku tapjacking poprzez tworzenie częściowo nakładającego się okna. Umożliwia to przejęcie kontroli nad interakcją użytkownika oraz dostęp do dowolnych plików z prywatnego magazynu danych.

pub. 2016-06-13
9.6
CVSS
CRITICAL
CVE-2021-21132

Nieprawidłowa implementacja w narzędziach deweloperskich (DevTools) Google Chrome umożliwia zdalnemu atakującemu potencjalne wykonanie sandbox escape za pośrednictwem spreparowanego rozszerzenia Chrome. Podatność jest krytyczna, ponieważ pozwala na wyjście poza izolowane środowisko przeglądarki.

pub. 2021-02-09
9.6
CVSS
CRITICAL
CVE-2021-21111

Niewystarczające egzekwowanie polityki w komponencie WebUI przeglądarki Google Chrome umożliwiało ucieczkę z piaskownicy (sandbox escape) za pośrednictwem spreparowanego rozszerzenia Chrome. Podatność jest krytyczna, ponieważ może prowadzić do pełnego przejęcia kontroli nad systemem ofiary.

pub. 2021-01-08
9.3
CVSS
CRITICAL
CVE-2026-44727

Jupyter Server w wersjach przed 2.20 jest podatny na stored XSS wstrzyknięty przez notebooki zawierające payload HTML w wyjściu display_data. Podatność pozwala atakującemu uzyskać dostęp do ciasteczek sesji, pełne uprawnienia do API oraz zdalne wykonanie kodu przez kernel.

pub. 2026-06-22
9.1
CVSS
CRITICAL
CVE-2024-10004

Podatność w Firefox dla iOS powoduje nieprawidłowe wyświetlanie ikony kłódki HTTPS podczas otwierania zewnętrznych linków HTTP, gdy przeglądarka była wcześniej zamknięta z otwartą kartą HTTPS. Może to wprowadzać użytkowników w błąd co do bezpieczeństwa przeglądanego połączenia.

pub. 2024-10-15
8.8
CVSS
HIGH
CVE-2023-41897

Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header, which specifies whether the web page is allowed to be framed. The omission of this and correlating headers facilitates covert clickjacking attacks and alternative exploit opportunities, such as the vector described in this security advisory. This fault incurs major risk, considering the ability to trick users into installing an external and malicious add-on with minimal user interaction, which would enable Remote Code Execution (RCE) within the Home Assistant application. This issue has been addressed in version 2023.9.0 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

pub. 2023-10-19
8.8
CVSS
HIGH
CVE-2022-3167

Improper Restriction of Rendered UI Layers or Frames in GitHub repository ikus060/rdiffweb prior to 2.4.1.

pub. 2022-09-08
8.8
CVSS
HIGH
CVE-2021-3734

yourls is vulnerable to Improper Restriction of Rendered UI Layers or Frames

pub. 2021-08-26
8.8
CVSS
HIGH
CVE-2021-22866

A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than was displayed to the user during approval. To exploit this vulnerability, an attacker would need to create a GitHub App on the instance and have a user authorize the application through the web authentication flow. All permissions being granted would properly be shown during the first authorization, but in certain circumstances, if the user revisits the authorization flow after the GitHub App has configured additional user-level permissions, those additional permissions may not be shown, leading to more permissions being granted than the user potentially intended. This vulnerability affected GitHub Enterprise Server 3.0.x prior to 3.0.7 and 2.22.x prior to 2.22.13. It was fixed in versions 3.0.7 and 2.22.13. This vulnerability was reported via the GitHub Bug Bounty program.

pub. 2021-05-14
8.8
CVSS
HIGH
CVE-2015-5686

Parts of the Puppet Enterprise Console 3.x were found to be susceptible to clickjacking and CSRF (Cross-Site Request Forgery) attacks. This would allow an attacker to redirect user input to an untrusted site or hijack a user session.

pub. 2020-02-27
8.8
CVSS
HIGH
CVE-2018-18496

When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This vulnerability affects Firefox < 64.

pub. 2019-02-28
8.6
CVSS
HIGH
CVE-2026-0007

In writeToParcel of WindowInfo.cpp, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

pub. 2026-03-02
8.2
CVSS
HIGH
CVE-2026-70486

W Open WebUI w wersjach od 0.9.0 do 0.10.x podgląd plików HTML w terminalu był osadzany w elemencie iframe z jednocześnie włączonymi uprawnieniami allow-same-origin oraz allow-scripts, co tworzyło podatność XSS. Umożliwia to uwierzytelnionemu atakującemu kradzież tokenu sesji ofiary i przejęcie jej konta.

pub. 2026-08-04
8.2
CVSS
HIGH
CVE-2021-44683

The DuckDuckGo browser 7.64.4 on iOS allows Address Bar Spoofing due to mishandling of the JavaScript window.open function (used to open a secondary browser window). This could be exploited by tricking users into supplying sensitive information such as credentials, because the address bar would display a legitimate URL, but content would be hosted on the attacker's web site.

pub. 2022-03-25
8.2
CVSS
HIGH
CVE-2019-16371

LogMeIn LastPass before 4.33.0 allows attackers to construct a crafted web site that captures the credentials for a victim's account on a previously visited web site, because do_popupregister can be bypassed via clickjacking.

pub. 2019-09-16
8.1
CVSS
HIGH
CVE-2026-74978

Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

pub. 2026-08-18
8.1
CVSS
HIGH
CVE-2026-58595

Podatność w Microsoft Bing App dla iOS pozwala nieuwierzytelnionemu atakującemu na przeprowadzenie ataku spoofing przez sieć. Wynika z nieprawidłowego ograniczenia renderowanych warstw lub ramek interfejsu użytkownika (CWE-1021).

pub. 2026-07-14
8.1
CVSS
HIGH
CVE-2024-11700

Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulnerability affects Firefox < 133 and Thunderbird < 133.

pub. 2024-11-26
Pokazano 20 z 482 podatności
Informacje
ID: CWE-1021
Typ: Base
Podatności: 482
MITRE CWE ↗
← Słownik CWE