BETA O Shoulder está em beta — Os resultados às vezes podem estar incorretos. Seu feedback molda o que corrigimos a seguir. Compartilhar feedback
#8 A08:2021

Software and Data Integrity Failures

Software and data integrity failures relate to code and infrastructure that does not protect against integrity violations, including insecure deserialization.

Visão Geral

A new category for 2021, focuses on making assumptions related to software updates, critical data, and CI/CD pipelines without verifying integrity. Also includes Insecure Deserialization from 2017.

Como Atacantes Exploram Isso

Entender padrões de ataque ajuda você a construir melhores defesas. Estas são as técnicas que equipes de segurança monitoram.

Insecure deserialization

Untrusted data is deserialized by the application, potentially leading to remote code execution.

Sinal de detecção: Serialized object patterns in requests, unexpected class instantiation errors

CI/CD pipeline compromise

Attackers inject malicious code through compromised build systems or update mechanisms.

Sinal de detecção: Unexpected changes in build outputs, modified binaries without corresponding source changes

Como Prevenir

  • Use digital signatures to verify software or data is from expected source
  • Ensure libraries and dependencies are from trusted repositories
  • Use software supply chain security tools to verify components
  • Ensure CI/CD pipeline has proper segregation and access control
  • Ensure unsigned or unencrypted serialized data is not sent to untrusted clients

CWEs com Detecção Shoulder (2)

Estes CWEs têm regras de detecção Shoulder. Clique para ver vulnerabilidades específicas e correções.

Outros CWEs Mapeados (8)

Estes CWEs estão mapeados para esta categoria mas ainda não têm regras Shoulder.