Software and Data Integrity Failures
Software and data integrity failures relate to code and infrastructure that does not protect against integrity violations, including insecure deserialization.
अवलोकन
A new category for 2021, focuses on making assumptions related to software updates, critical data, and CI/CD pipelines without verifying integrity. Also includes Insecure Deserialization from 2017.
हमलावर इसका शोषण कैसे करते हैं
हमले के पैटर्न समझने से बेहतर सुरक्षा बनाने में मदद मिलती है। ये वे तकनीकें हैं जिन पर सुरक्षा टीमें नज़र रखती हैं।
Insecure deserialization
Untrusted data is deserialized by the application, potentially leading to remote code execution.
CI/CD pipeline compromise
Attackers inject malicious code through compromised build systems or update mechanisms.
कैसे रोकें
- Use digital signatures to verify software or data is from expected source
- Ensure libraries and dependencies are from trusted repositories
- Use software supply chain security tools to verify components
- Ensure CI/CD pipeline has proper segregation and access control
- Ensure unsigned or unencrypted serialized data is not sent to untrusted clients
Shoulder पहचान वाले CWE (2)
इन CWE में Shoulder पहचान नियम हैं। विशिष्ट भेद्यताएँ और समाधान देखने के लिए क्लिक करें।
अन्य मैप किए गए CWE (8)
ये CWE इस श्रेणी से मैप किए गए हैं लेकिन अभी तक Shoulder नियम नहीं हैं।