What is CWE-1021?
A web application fails to restrict, or incorrectly restricts, frames or user interface layers that belong to another application or domain.
A web application fails to restrict, or incorrectly restricts, frames or user interface layers that belong to another application or domain.
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.
The weakness occurs when content can be rendered within, over, or alongside a user interface from another application or domain without adequate restrictions. An attacker can use this behavior to disguise the location or purpose of a control and induce a user to interact with an unintended underlying application. The issue is commonly associated with clickjacking and UI redress attacks; the comparable mobile scenario is often called tapjacking, where the user taps a manipulated interface.
This is an implementation-phase weakness affecting web-based applications and is not specific to a programming language or technology. Its defining behavior is the failure to enforce which external applications or domains may frame or otherwise render the application, including through frames, overlays, or related embedding elements. The record also identifies clickjacking, UI redress attack, and tapjacking as associated terms, with tapjacking referring to touch-based interaction in mobile applications.
The primary impact is on access control. By causing a user to activate concealed or misleading controls, an attacker may help gain privileges or assume an identity, bypass a protection mechanism, read application data, or modify application data. The specific result depends on the functionality exposed by the underlying application, such as changing privacy settings in a social media application.
| Impact | Scope | Explanation |
|---|---|---|
| Gain Privileges or Assume Identity, Bypass Protection Mechanism, Read Application Data, Modify Application Data | Access Control | An attacker can trick a user into performing actions that are masked and hidden from the user's view. The impact varies widely, depending on the functionality of the underlying application. For example, in a social media application, clickjacking could be used to trick the user into changing privacy settings. |
Apply layered restrictions during implementation:
X-Frame-Options to specify which domains may frame the application, while accounting for limitations and implementation gaps, including requirements to allow multiple domains.X-Frame-Options, use a frame-breaker script on pages that should not be framed. This is not sufficient by itself because frame-breaking scripts can be bypassed and may not correctly handle multiple nested frames.frame-ancestors or frame-src directive to control permitted embedded content.object, embed, or applet elements, in addition to controlling frames and iframes.Automated static analysis, also known as Static Application Security Testing, can identify some instances without executing the application. It can model data flow and control flow in source or compiled code and search for vulnerable patterns connecting input sources to sinks that interact with external components or lower layers. The method is rated highly effective in the record, but the record describes it as capable of finding some instances rather than all instances.
| Method | Approach | Effectiveness |
|---|---|---|
| Automated Static Analysis | Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.) | High |
The official record provides these representative examples, not an exhaustive list:
CVE-2017-7440: A desktop application's email preview feature allowed clickjacking through a crafted email message.CVE-2017-5697: A hardware or firmware product had insufficient clickjacking protection in its web user interface.CVE-2017-4015: A data-loss prevention product was vulnerable to clickjacking through an HTTP response header.CVE-2016-2496: Tapjacking in a mobile operating system permission dialog enabled access to private storage through a partially overlapping window.CVE-2015-1241: A web browser was affected by tapjacking involving page navigation and touch or gesture events.CVE-2017-0492: A mobile operating system's system UI allowed a malicious application to create a full-screen UI overlay and gain privileges.Below are representative vulnerabilities related to this CWE, prioritized by severity.
CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScanen