Falhas do tipo CWE-506

101 resultados

Código malicioso embutido

É quando código malicioso é intencionalmente inserido dentro de um componente legítimo de software, muitas vezes durante o desenvolvimento, build ou distribuição. O risco é que a aplicação executa lógica destrutiva ou de exfiltração de dados sem que o usuário final (ou até o proprietário) tenha consciência.

Exemplo

Um desenvolvedor comprometido adiciona uma função que envia credenciais de usuários para um servidor externo sempre que um formulário de login é submetido. O código fica dorminhoco na base de código e passa por code review se o revisor não estiver atento ou também estiver comprometido.

Como mitigar

Implemente verificação de integridade de código (assinatura digital de builds), auditoria rigorosa de mudanças via git history e acesso restrito ao repositório, testes de segurança automatizados que detectem chamadas suspeitas para servidores externos, e isolamento de ambientes de desenvolvimento e produção.

CVE-2017-16069nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16054`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16072nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16060babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16202The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installatEPSS 1.2%CVE-2017-16049`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16064node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16068ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16074crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16065openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16075http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16070nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16046`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16204The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.EPSS 1.1%CVE-2017-16076proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16058gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16053`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16063node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16071nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16067node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%