Fallos del tipo CWE-506

101 resultados

Código malicioso incorporado

É quando código malicioso é deliberadamente inserido dentro de um software legítimo durante o desenvolvimento, compilação ou distribuição. O atacante consegue executar ações não autorizadas (roubo de dados, backdoors, sabotagem) porque o código malicioso está embutido no binário confiável.

Ejemplo

Um desenvolvedor com acesso ao repositório insere silenciosamente código que envia credenciais de usuários para um servidor externo; ou um fornecedor de biblioteca terceira injeta um keylogger que ativa após a instalação. A vítima só descobre quando o dano já está feito.

Cómo mitigar

Implemente: (1) revisão de código rigorosa e assinatura digital de commits; (2) análise estática e dinâmica automática (SAST/DAST) no pipeline CI/CD; (3) verificação de integridade e autenticidade de dependências e pacotes; (4) auditoria de acessos a repositórios e build systems; (5) sandboxing e princípio de menor privilégio em produção.

CVE-2017-16052`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%CVE-2017-16048`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%CVE-2017-16074crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%CVE-2017-16069nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%CVE-2017-16054`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%CVE-2017-16072nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%CVE-2017-16060babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%CVE-2017-16049`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%CVE-2017-16064node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%CVE-2017-16068ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%CVE-2017-16065openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%CVE-2017-16070nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%CVE-2017-16075http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%CVE-2017-16202The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installatEPSS 1.0%CVE-2017-16076proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%CVE-2017-16204The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.EPSS 1.0%CVE-2017-16053`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%CVE-2017-16063node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%CVE-2017-16058gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%CVE-2017-16050`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.0%