OWASP / Top10

Official OWASP Top 10 Document Repository
Other
4.27k stars 827 forks source link

Remove example about default credentials from A05 2021 #783

Open drhankey opened 5 months ago

drhankey commented 5 months ago

As example for security misconfiguration is listed "Default accounts and their passwords are still enabled and unchanged". However, this is part of A07, specifically CWE-1392 Use of Default Credentials.

I suggest to remove this line: https://github.com/OWASP/Top10/blob/7c7288f5d7a4222c44b2df8fa8799ad1fb1a43da/2021/docs/A05_2021-Security_Misconfiguration.md?plain=1#L27