OWASP Top 10 Overview
What is the OWASP Top 10?
OWASP (the Open Worldwide Application Security Project) is a non-profit that publishes free security guidance. Its Top 10 is a ranked list of the most critical web application risks, built from real data. Banks, fintechs and regulators in Nigeria and worldwide use it as a common language, and many job interviews and bug-bounty reports refer to it.
This lesson uses the widely referenced 2021 edition. OWASP updates the list every few years, so check owasp.org for the latest, but the ideas below stay relevant.
Legal note: Only test applications you own or have written permission to test.
The Ten Risks
A01: Broken Access Control
Users can act outside their permissions. Example: a customer changes /invoice?id=1001 to id=1002 and reads someone else's invoice (this is called IDOR). It is the number one risk. Fix: check permissions on the server for every request, deny by default.
A02: Cryptographic Failures
Sensitive data is not protected properly: plain HTTP, weak or missing encryption, passwords stored in plain text or with fast hashes like MD5. Fix: HTTPS everywhere, strong hashing (bcrypt, Argon2) and encrypt data at rest.
A03: Injection
Untrusted input is executed as a command or query: SQL injection, XSS, OS command injection. Example: ' OR '1'='1 in a login form. Fix: parameterised queries and output encoding. You practised both in the previous lessons.
A04: Insecure Design
The flaw is in the design, not the code. Example: a "forgot password" flow that reveals whether an email exists, or a transfer feature with no limit or confirmation. Fix: threat modelling and security requirements before coding.
A05: Security Misconfiguration
Default passwords, open cloud storage, verbose error pages, unnecessary services. Example: an admin panel left with admin/admin, or an S3 bucket set to public. Fix: hardened, repeatable configuration and regular scans.
A06: Vulnerable and Outdated Components
Using libraries or plugins with known flaws. Example: the 2017 Equifax breach came from an unpatched Apache Struts component, and Log4Shell (2021) hit millions of Java apps. Fix: an inventory of dependencies, automatic update alerts (Dependabot, npm audit).
A07: Identification and Authentication Failures
Weak passwords allowed, no rate limiting, session IDs in URLs, no multi-factor authentication. Fix: MFA, lockouts, strong password rules and secure session handling.
A08: Software and Data Integrity Failures
Trusting code or data without checking it. Example: the SolarWinds supply-chain attack (2020) or auto-updates from an unsigned source. Fix: signed packages, verified CI/CD pipelines and integrity checks.
A09: Security Logging and Monitoring Failures
Attacks succeed because nobody notices. Breaches are often discovered months after they start. Fix: log logins, failures and high-value actions, centralise the logs and alert on suspicious patterns.
A10: Server-Side Request Forgery (SSRF)
The server is tricked into requesting an internal URL. Example: an "import image from URL" feature is used to reach a cloud metadata address like http://169.254.169.254, and the attacker steals cloud credentials, as in the 2019 Capital One breach. Fix: allow-list destinations and block internal addresses.
A Nigerian and Global Lens
Nigerian fintechs and banks handle instant transfers, BVN and NIN data, so A01 (access control), A07 (authentication) and A09 (logging) matter enormously. The central bank and payment standards expect secure development and testing. The same list applies to a shop in Lagos, a health app in Nairobi or a SaaS company in Toronto, because the bugs are the same everywhere.
How to Use the List
- Developers: treat it as a checklist while building and reviewing code.
- Testers and bug hunters: use it to decide what to test first.
- Managers: use it to prioritise fixes and to ask vendors better questions.
Remember that the list is an awareness document, not a complete standard. For deeper testing, use the OWASP Application Security Verification Standard (ASVS) and the Web Security Testing Guide.
Practice: Match the Scenario
In the editor on the right, match each real-world scenario to its OWASP category. Explain to yourself why the other options do not fit, since that is how you learn the differences.
Try it yourself
Key Takeaways
- The OWASP Top 10 is a ranked, data-driven list of the most critical web application risks and a common language for developers and testers.
- Broken Access Control (A01) is first: always check permissions on the server for every request, and deny by default.
- Injection (A03) covers SQL injection and XSS. The fixes are parameterised queries and output encoding.
- Many risks are about process, not code: insecure design, misconfiguration, outdated components and missing logging and monitoring.
- It is an awareness list, not a full standard. Use OWASP ASVS and the Web Security Testing Guide for deeper work, and only test systems you are authorised to test.
Quick Quiz
1.Which risk is ranked first in the OWASP Top 10 (2021)?
2.A developer relies on an old JavaScript library that has a published vulnerability and has not updated it. Which category is this?
3.An 'import image from URL' feature is abused to make the server call an internal cloud metadata address. What is this attack?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx