BÊTA Shoulder est en bêta — Les résultats peuvent parfois être incorrects. Vos retours façonnent ce que nous corrigeons ensuite. Donner mon avis
#6 A06:2021

Vulnerable and Outdated Components

Components such as libraries, frameworks, and other software modules run with the same privileges as the application. If a vulnerable component is exploited, it can cause serious data loss.

Aperçu

Previously titled Using Components with Known Vulnerabilities. It is #2 in the Top 10 community survey but also had enough data to make the Top 10 via data analysis.

Comment les Attaquants Exploitent Cela

Comprendre les patterns d'attaque vous aide à construire de meilleures défenses. Ce sont les techniques que les équipes de sécurité surveillent.

Known vulnerability exploitation

Attackers target publicly disclosed vulnerabilities in popular libraries before applications are patched.

Signal de détection: Exploit attempts matching known CVE patterns, targeting specific library endpoints

Supply chain compromise

Malicious code is introduced through compromised or typosquatted packages.

Signal de détection: Unexpected network connections, unusual package behaviors

Comment Prévenir

  • Remove unused dependencies, features, components, and documentation
  • Continuously inventory component versions and their dependencies
  • Monitor sources like CVE and NVD for vulnerabilities in components
  • Only obtain components from official sources over secure links
  • Monitor for unmaintained libraries that don't receive security patches
  • Use virtual patching via web application firewall if needed

CWEs avec Détection Shoulder (1)

Ces CWEs ont des règles de détection Shoulder. Cliquez pour voir les vulnérabilités spécifiques et les correctifs.

Autres CWEs Associés (2)

Ces CWEs sont associés à cette catégorie mais n'ont pas encore de règles Shoulder.