Common Weakness Enumeration

    CWE Definition / CWE-942

    CWE-942: Permissive Cross-domain Security Policy with Untrusted Domains

    The product uses a web-client protection mechanism such as a Content Security Policy (CSP) or cross-domain policy file, but the policy includes untrusted domains with which the web client is allowed to communicate.

    Published:5 Jun 2014
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-863: Incorrect Authorization

    CWE-923: Improper Restriction of Communication Channel to Intended Endpoints

    CWE-183: Permissive List of Allowed Inputs

    CWE-668: Exposure of Resource to Wrong Sphere