BETA O Shoulder está em beta — Os resultados às vezes podem estar incorretos. Seu feedback molda o que corrigimos a seguir. Compartilhar feedback
#6 A06:2021

Vulnerable and Outdated Components

Components such as libraries, frameworks, and other software modules run with the same privileges as the application. If a vulnerable component is exploited, it can cause serious data loss.

Visão Geral

Previously titled Using Components with Known Vulnerabilities. It is #2 in the Top 10 community survey but also had enough data to make the Top 10 via data analysis.

Como Atacantes Exploram Isso

Entender padrões de ataque ajuda você a construir melhores defesas. Estas são as técnicas que equipes de segurança monitoram.

Known vulnerability exploitation

Attackers target publicly disclosed vulnerabilities in popular libraries before applications are patched.

Sinal de detecção: Exploit attempts matching known CVE patterns, targeting specific library endpoints

Supply chain compromise

Malicious code is introduced through compromised or typosquatted packages.

Sinal de detecção: Unexpected network connections, unusual package behaviors

Como Prevenir

  • Remove unused dependencies, features, components, and documentation
  • Continuously inventory component versions and their dependencies
  • Monitor sources like CVE and NVD for vulnerabilities in components
  • Only obtain components from official sources over secure links
  • Monitor for unmaintained libraries that don't receive security patches
  • Use virtual patching via web application firewall if needed

CWEs com Detecção Shoulder (1)

Estes CWEs têm regras de detecção Shoulder. Clique para ver vulnerabilidades específicas e correções.

Outros CWEs Mapeados (2)

Estes CWEs estão mapeados para esta categoria mas ainda não têm regras Shoulder.