BETA Shoulder ist in der Beta — Befunde können manchmal falsch sein. Dein Feedback bestimmt, was wir als Nächstes beheben. Feedback teilen
#6 A06:2021

Vulnerable and Outdated Components

Components such as libraries, frameworks, and other software modules run with the same privileges as the application. If a vulnerable component is exploited, it can cause serious data loss.

Überblick

Previously titled Using Components with Known Vulnerabilities. It is #2 in the Top 10 community survey but also had enough data to make the Top 10 via data analysis.

Wie Angreifer dies ausnutzen

Das Verstehen von Angriffsmustern hilft Ihnen, bessere Verteidigungen aufzubauen. Dies sind die Techniken, die Sicherheitsteams überwachen.

Known vulnerability exploitation

Attackers target publicly disclosed vulnerabilities in popular libraries before applications are patched.

Erkennungssignal: Exploit attempts matching known CVE patterns, targeting specific library endpoints

Supply chain compromise

Malicious code is introduced through compromised or typosquatted packages.

Erkennungssignal: Unexpected network connections, unusual package behaviors

Wie Sie vorbeugen

  • Remove unused dependencies, features, components, and documentation
  • Continuously inventory component versions and their dependencies
  • Monitor sources like CVE and NVD for vulnerabilities in components
  • Only obtain components from official sources over secure links
  • Monitor for unmaintained libraries that don't receive security patches
  • Use virtual patching via web application firewall if needed

CWEs mit Shoulder-Erkennung (1)

Diese CWEs haben Shoulder-Erkennungsregeln. Klicken Sie, um spezifische Schwachstellen und Korrekturen zu sehen.

Andere zugeordnete CWEs (2)

Diese CWEs sind dieser Kategorie zugeordnet, haben aber noch keine Shoulder-Regeln.