Software and Data Integrity Failures
Software and data integrity failures relate to code and infrastructure that does not protect against integrity violations, including insecure deserialization.
Visão Geral
A new category for 2021, focuses on making assumptions related to software updates, critical data, and CI/CD pipelines without verifying integrity. Also includes Insecure Deserialization from 2017.
Como Atacantes Exploram Isso
Entender padrões de ataque ajuda você a construir melhores defesas. Estas são as técnicas que equipes de segurança monitoram.
Insecure deserialization
Untrusted data is deserialized by the application, potentially leading to remote code execution.
CI/CD pipeline compromise
Attackers inject malicious code through compromised build systems or update mechanisms.
Como Prevenir
- Use digital signatures to verify software or data is from expected source
- Ensure libraries and dependencies are from trusted repositories
- Use software supply chain security tools to verify components
- Ensure CI/CD pipeline has proper segregation and access control
- Ensure unsigned or unencrypted serialized data is not sent to untrusted clients
CWEs com Detecção Shoulder (2)
Estes CWEs têm regras de detecção Shoulder. Clique para ver vulnerabilidades específicas e correções.
Outros CWEs Mapeados (8)
Estes CWEs estão mapeados para esta categoria mas ainda não têm regras Shoulder.