Disabled Lightning Locker

Overview

Lightning Locker is the built-in security architecture for Lightning components. It enhances security by promoting several best practices, including eliminating access to specific APIs and framework internals. Lightning Locker can be disabled for an Aura component by setting the Salesforce API version to 39.0 or lower for the component. If an element is set to at least API version 40.0, Lightning Locker is enabled.

Business Impact

Increased risk of data breaches, financial loss, and reputational harm. Eroding customer trust and confidence.

Resources

Frequent

Incidence

How common is this issue?
13%7%
arrow down5%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
3 years1 year
arrow down58%
shorter
BenchmarkWith Clayton

Frameworks

TrustediconSecureiconSession SecurityiconSession ManagementiconA05:2021 – Security Misconfigurationicon