ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringHard

A security auditor is reviewing a custom-developed application and identifies a vulnerability where the application explicitly trusts user-supplied data in HTTP headers, leading to potential privilege escalation if a malicious user crafts specific header values. This vulnerability falls under which category of Web-based systems vulnerabilities?

  1. AServer-Side Request Forgery (SSRF)
  2. BBroken Access Control
  3. CSecurity Misconfiguration
  4. DInsecure Design
Show answer & explanation

Correct answer: D. Insecure Design

This scenario describes a flaw in the fundamental design of the application where trust boundaries are not properly established. Explicitly trusting user-supplied data in HTTP headers without validation reflects a design decision that fails to adequately consider threats, fitting the 'Insecure Design' category from OWASP Top 10, rather than a misconfiguration or an isolated access control issue.

Why the other options are wrong

  • A. SSRF involves the server making unauthorized requests to internal/external resources, not directly about trusting user headers for privilege escalation.
  • B. Broken Access Control relates to faulty enforcement of permissions, not necessarily trusting header data fundamentally.
  • C. Security Misconfiguration refers to incorrect settings or default configurations, not a flaw in the application's inherent trust model.

Insecure Design (OWASP)

A category of web application vulnerabilities that focuses on design flaws related to missing or ineffective control design.

  • Often stems from a lack of threat modeling or secure design patterns.
  • Not about implementation bugs, but about fundamental architectural weaknesses.
  • Can lead to a wide range of vulnerabilities if the underlying design is flawed.

Memory trick: OWASP: The 'O'utstanding 'W'atchdog 'A'lerting 'S'ecurity 'P'rofessionals.

More Security Architecture and Engineering questions