SecurityWeek reports that the Open Web Application Security Project has added Mishandling of Exceptional Conditions and Software Supply Chain Failures to the latest revision of its Top 10 list of critical web application issues, which also reshuffles the order of risks.Broken Access Control remains at the top, as it did in 2021, and now incorporates the former server-side request forgery category, which previously held the final position, while Security Misconfiguration moved from fifth place to second. Software Supply Chain Failures appears in third as an expanded version of Vulnerable and Outdated Components. Moreover, Cryptographic Failures, Injection, and Insecure Design landed at fourth, fifth, and sixth, respectively. Authentication Failures, Software or Data Integrity Failures, and Logging & Alerting Failures continue to occupy the seventh through ninth positions.OWASP says several categories were reshaped due to a revised data-collection method that drew from 589 CWEs and incorporated CVE-based exploitability and impact scoring. Eight categories stemmed from this data, while two came from the Top 10 community survey. OWASP's list is available for public feedback until November 20.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds





