Vulnerable and Outdated Components
Components such as libraries, frameworks, and other software modules run with the same privileges as the application. If a vulnerable component is exploited, it can cause serious data loss.
अवलोकन
Previously titled Using Components with Known Vulnerabilities. It is #2 in the Top 10 community survey but also had enough data to make the Top 10 via data analysis.
हमलावर इसका शोषण कैसे करते हैं
हमले के पैटर्न समझने से बेहतर सुरक्षा बनाने में मदद मिलती है। ये वे तकनीकें हैं जिन पर सुरक्षा टीमें नज़र रखती हैं।
Known vulnerability exploitation
Attackers target publicly disclosed vulnerabilities in popular libraries before applications are patched.
Supply chain compromise
Malicious code is introduced through compromised or typosquatted packages.
कैसे रोकें
- Remove unused dependencies, features, components, and documentation
- Continuously inventory component versions and their dependencies
- Monitor sources like CVE and NVD for vulnerabilities in components
- Only obtain components from official sources over secure links
- Monitor for unmaintained libraries that don't receive security patches
- Use virtual patching via web application firewall if needed
Shoulder पहचान वाले CWE (1)
इन CWE में Shoulder पहचान नियम हैं। विशिष्ट भेद्यताएँ और समाधान देखने के लिए क्लिक करें।
अन्य मैप किए गए CWE (2)
ये CWE इस श्रेणी से मैप किए गए हैं लेकिन अभी तक Shoulder नियम नहीं हैं।