What is a Security Vulnerability?
A security vulnerability is a weakness in software, infrastructure, configuration, or process that an attacker may exploit.
Examples include:
- Broken access control
- SQL injection
- Weak authentication
- Exposed secrets
- Cloud misconfiguration
Short answer: A vulnerability is a weakness that can be exploited to compromise a system.
What Is the Difference Between Vulnerability, Threat, and Risk?
A vulnerability is a weakness.
A threat is something that may exploit that weakness.
A risk is the possible damage if the threat successfully exploits the vulnerability.
Example:
Unlocked Door → Vulnerability Intruder → Threat Stolen Data → Risk
Typical Data Flow Leading to a Vulnerability Exploit
User Input Input Validation Application Processing Database Attacker
User Input
Input Validation
Application Processing
Database
Attacker
What Is SQL Injection?
SQL Injection happens when unsafe user input changes the intended SQL query.
For example, building SQL directly from user input can allow malicious input to affect the query.
A common prevention method is:
- Parameterized queries
- Prepared statements
- Input validation
- Least-privilege database accounts
Interview answer: Never build SQL queries by directly concatenating untrusted input.
What Is Cross-Site Scripting — XSS?
XSS happens when attacker-controlled content is executed as JavaScript in another user’s browser.
Common types include:
- Stored XSS
- Reflected XSS
- DOM-based XSS
Possible protections include:
- Output encoding
- Input validation
- Content Security Policy
- Safe templating frameworks
What Is CSRF?
Cross-Site Request Forgery tricks an authenticated user’s browser into sending an unwanted request.
For example, a logged-in user may unknowingly trigger:
Change Email Transfer Money Delete Account
Possible protections include:
- CSRF tokens
- SameSite cookies
- Re-authentication for sensitive actions
What Is SSRF?
Server-Side Request Forgery happens when an attacker tricks the server into making requests to unintended systems.
For example:
User Input ↓ Application Server ↓ Internal Service
This can be dangerous because internal services may trust requests coming from the application server.
Possible protections include:
- URL allowlists
- Blocking private/internal address ranges where appropriate
- Network segmentation
- Strict input validation
What Is Broken Access Control?
Broken access control happens when users can access resources or actions they are not authorized to use.
Example:
/user/100
A user changes it to:
/user/101
and sees another user’s data.
The fix is not simply hiding the ID.
The server must verify that the logged-in user has permission to access that resource.
Authentication vs Authorization — What Is the Difference?
Authentication answers:
Who are you?
Authorization answers:
What are you allowed to do?
Example:
Login successfully → AuthenticationAccess admin page → Authorization
A user may be authenticated but still not authorized to access admin functionality.
What Is the Principle of Least Privilege?
Least privilege means giving users, applications, and services only the minimum permissions they need.
For example, an application that only reads data should not receive database administrator privileges.
This reduces the damage if an account or service is compromised.
Why Should Secrets Not Be Stored in Source Code?
Secrets may include:
- API keys
- Database passwords
- Cloud credentials
- Private tokens
If committed to Git, they may appear in repository history even after the visible line is removed.
Use:
- Secret managers
- Environment configuration
- Credential rotation
- Restricted access
Important: If a real secret is exposed, rotate or revoke it rather than only deleting it from the code.
What Is a WAF?
A Web Application Firewall filters HTTP and HTTPS traffic before it reaches the application.
Example:
Internet ↓ WAF ↓ Application
A WAF may help block:
- Known malicious requests
- Suspicious patterns
- Some automated attacks
- Unwanted traffic
However, a WAF does not replace secure application code.
Can Security Vulnerabilities Be Completely Eliminated?
No system can realistically guarantee that it will never contain a vulnerability.
The goal is to reduce risk through:
- Secure design
- Secure coding
- Testing
- Patching
- Monitoring
- Least privilege
- Defense in depth
- Fast incident response
Security is an ongoing process, not a one-time task.
When to Focus on Security Vulnerability Assessment
Security assessments should be integral during software development lifecycle phases: design, implementation, testing, and deployment. Critical systems, public-facing applications, and those handling sensitive data require heightened scrutiny.
Summary
Understanding security vulnerabilities is fundamental for building resilient systems. Recognizing common vulnerability types, enforcing security boundaries, avoiding common mistakes, and applying best practices enable professionals to mitigate risks effectively. Awareness of trade-offs and timely assessments ensures balanced and secure software solutions.
Key Takeaways
- Security vulnerabilities are weaknesses exploitable by attackers to compromise systems.
- Common vulnerabilities include SQL Injection, XSS, buffer overflows, and broken authentication.
- Proper input validation and security boundaries are critical defenses.
- Regular assessments and adherence to best practices reduce vulnerability risks.
- Balancing security with usability and performance requires careful trade-offs.
Frequently Asked Questions
How can I identify security vulnerabilities in my code?+
Use static and dynamic analysis tools, conduct code reviews focusing on security, perform penetration testing, and stay updated with vulnerability databases like CVE and OWASP Top 10.
What is the difference between a vulnerability and an exploit?+
A vulnerability is a weakness in a system, while an exploit is a method or code that takes advantage of that vulnerability to cause harm.
Are all vulnerabilities equally critical?+
No, vulnerabilities vary in severity based on factors like ease of exploitation, potential impact, and exposure. Risk assessment helps prioritize remediation.