目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-1021 不当限制渲染UI层或帧 类漏洞列表 130

CWE-1021 不当限制渲染UI层或帧 类弱点 130 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-1021属于界面层限制不当漏洞,指Web应用未正确限制来自其他应用或域名的框架对象及UI层。攻击者常利用此缺陷,通过嵌入恶意iframe或覆盖合法界面,实施点击劫持或内容注入,诱导用户交互以窃取数据或执行未授权操作。开发者应避免直接嵌入不可信源,通过设置X-Frame-Options响应头或Content-Security-Policy策略,严格限制页面被帧嵌入的范围,从而有效隔离不同域名的UI层,保障用户界面完整性。

MITRE CWE 官方描述
CWE:CWE-1021 渲染 UI 层或框架的限制不当 英文:Web 应用程序未对属于其他应用程序或域名的 frame 对象或 UI 层进行限制,或限制不当。
常见影响 (1)
Access Control Gain Privileges or Assume Identity, Bypass Protection Mechanism, Read Application Data, Modify Application Data
An attacker can trick a user into performing actions that are masked and hidden from the user's view. The impact varies widely, depending on the functionality of the underlying application. For example, in a social media application, clickjacking could be used to trick the user into changing privacy…
缓解措施 (4)
Implementation The use of X-Frame-Options allows developers of web content to restrict the usage of their application within the form of overlays, frames, or iFrames. The developer can indicate from which domains can frame the content. The concept of X-Frame-Options is well documented, but implementation of this protection mechanism is in development to cover gaps. There is a need for allowing frames from multip…
Implementation A developer can use a "frame-breaker" script in each page that should not be framed. This is very helpful for legacy browsers that do not support X-Frame-Options security feature previously mentioned. It is also important to note that this tactic has been circumvented or bypassed. Improper usage of frames can persist in the web application through nested frames. The "frame-breaking" script does no…
Implementation This defense-in-depth technique can be used to prevent the improper usage of frames in web applications. It prioritizes the valid sources of data to be loaded into the application through the usage of declarative policies. Based on which implementation of Content Security Policy is in use, the developer should use the "frame-ancestors" directive or the "frame-src" directive to mitigate this weakne…
Implementation In addition to frames or iframes as previously mentioned, the web application is expected to place restrictions on whether it is allowed to be rendered within objects, embed, or applet elements.
CVE ID 标题 CVSS 风险等级 Published
CVE-2025-24310 JTEKT ELECTRONICS HMI ViewJet C-more 安全漏洞 — HMI ViewJet C-more series 9.6AI Critical AI 2025-04-04
CVE-2025-1923 Google Chrome 安全漏洞 — Chrome 4.3 - 2025-03-05
CVE-2025-1917 Google Chrome 安全漏洞 — Chrome 4.3 - 2025-03-05
CVE-2025-24874 SAP Commerce 安全漏洞 — SAP Commerce (Backoffice) 6.8 Medium 2025-02-11
CVE-2024-49796 IBM ApplinX 安全漏洞 — ApplinX 5.4 Medium 2025-02-05
CVE-2024-6466 NEC WebSAM DeploymentManager 安全漏洞 — WebSAM DeploymentManager 9.1 - 2025-01-21
CVE-2024-56436 Huawei HarmonyOS 权限许可和访问控制问题漏洞 — HarmonyOS 5.5 Medium 2025-01-08
CVE-2024-56435 Huawei HarmonyOS 信息泄露漏洞 — HarmonyOS 6.2 Medium 2025-01-08
CVE-2021-29827 IBM InfoSphere Information Server 安全漏洞 — InfoSphere Information Server 5.2 Medium 2024-12-18
CVE-2024-55888 Hush Line 安全漏洞 — hushline 7.1 High 2024-12-12
CVE-2024-54112 Huawei HarmonyOS 权限许可和访问控制问题漏洞 — HarmonyOS 5.5 Medium 2024-12-12
CVE-2024-54110 Huawei HarmonyOS 安全漏洞 — HarmonyOS 6.2 Medium 2024-12-12
CVE-2024-7404 GitLab Enterprise Edition(EE)和GitLab Community Edition(CE) 安全漏洞 — GitLab 6.8 Medium 2024-11-14
CVE-2024-10454 Clibo Manager 安全漏洞 — Clibo Manager 6.1 Medium 2024-10-31
CVE-2024-2177 GitLab CE/EE 安全漏洞 — GitLab 6.8 Medium 2024-07-09
CVE-2024-30109 HCL Technologies HCL DRYiCE AEX 安全漏洞 — DRYiCE AEX 3.7 Low 2024-06-28
CVE-2023-42011 IBM Sterling B2B Integrator 安全漏洞 — Sterling B2B Integrator Standard Edition 4.3 Medium 2024-06-27
CVE-2024-2383 ZenML 安全漏洞 — zenml-io/zenml 5.4AI Medium AI 2024-06-06
CVE-2023-47774 WordPress plugin Jetpack 安全漏洞 — Jetpack 5.4 Medium 2024-04-24
CVE-2024-3911 Welotec SMART EMS 安全漏洞 — SMART EMS 6.5 Medium 2024-04-23
CVE-2024-29981 Microsoft Edge 安全漏洞 — Microsoft Edge (Chromium-based) 4.3 Medium 2024-04-04
CVE-2024-28196 YourSpotify 安全漏洞 — your_spotify 6.5 Medium 2024-03-13
CVE-2024-26167 Microsoft Edge 安全漏洞 — Microsoft Edge for Android 4.3 Medium 2024-03-07
CVE-2024-1890 SMA Solar Technology AG Sunny WebBox 安全漏洞 — Sunny Webbox 6.4 Medium 2024-02-26
CVE-2024-0669 Plone 安全漏洞 — Plone CMS 6.3 Medium 2024-01-18
CVE-2023-6093 OnCell G3150A-LTE v1.3及 安全漏洞 — OnCell G3150A-LTE Series 5.3 Medium 2023-12-31
CVE-2023-4958 Red Hat stackrox 安全漏洞 — Red Hat Advanced Cluster Security 4.2 6.1 Medium 2023-12-12
CVE-2023-2265 Schweitzer Engineering Laboratories SEL-411L 安全漏洞 — SEL-411L 4.3 Medium 2023-11-30
CVE-2023-4956 Red Hat Quay 安全漏洞 — Red Hat Quay 3 6.5 Medium 2023-11-07
CVE-2023-36920 SAP Enable Now 安全漏洞 — SAP Enable Now 6.1 Medium 2023-10-30

CWE-1021(不当限制渲染UI层或帧) 是常见的弱点类别,本平台收录该类弱点关联的 130 条 CVE 漏洞。