ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringHard
A security auditor is reviewing a custom-developed application and identifies a vulnerability where the application explicitly trusts user-supplied data in HTTP headers, leading to potential privilege escalation if a malicious user crafts specific header values. This vulnerability falls under which category of Web-based systems vulnerabilities?
- AServer-Side Request Forgery (SSRF)
- BBroken Access Control
- CSecurity Misconfiguration
- DInsecure Design
Show answer & explanationAnswer & explanation
Correct answer: D. Insecure Design
This scenario describes a flaw in the fundamental design of the application where trust boundaries are not properly established. Explicitly trusting user-supplied data in HTTP headers without validation reflects a design decision that fails to adequately consider threats, fitting the 'Insecure Design' category from OWASP Top 10, rather than a misconfiguration or an isolated access control issue.
Why the other options are wrong
- A. SSRF involves the server making unauthorized requests to internal/external resources, not directly about trusting user headers for privilege escalation.
- B. Broken Access Control relates to faulty enforcement of permissions, not necessarily trusting header data fundamentally.
- C. Security Misconfiguration refers to incorrect settings or default configurations, not a flaw in the application's inherent trust model.
Insecure Design (OWASP)
A category of web application vulnerabilities that focuses on design flaws related to missing or ineffective control design.
- Often stems from a lack of threat modeling or secure design patterns.
- Not about implementation bugs, but about fundamental architectural weaknesses.
- Can lead to a wide range of vulnerabilities if the underlying design is flawed.
Memory trick: OWASP: The 'O'utstanding 'W'atchdog 'A'lerting 'S'ecurity 'P'rofessionals.