Application security

OWASP updates critical web app risk list

OWASP Top 10 released for 2013

SecurityWeek reports that the Open Web Application Security Project has added Mishandling of Exceptional Conditions and Software Supply Chain Failures to the latest revision of its Top 10 list of critical web application issues, which also reshuffles the order of risks.

Broken Access Control remains at the top, as it did in 2021, and now incorporates the former server-side request forgery category, which previously held the final position, while Security Misconfiguration moved from fifth place to second. Software Supply Chain Failures appears in third as an expanded version of Vulnerable and Outdated Components. Moreover, Cryptographic Failures, Injection, and Insecure Design landed at fourth, fifth, and sixth, respectively. Authentication Failures, Software or Data Integrity Failures, and Logging & Alerting Failures continue to occupy the seventh through ninth positions.

OWASP says several categories were reshaped due to a revised data-collection method that drew from 589 CWEs and incorporated CVE-based exploitability and impact scoring. Eight categories stemmed from this data, while two came from the Top 10 community survey. OWASP's list is available for public feedback until November 20.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds