Malicious Third Party Domain Detected

medium Web App Scanning Plugin ID 114358

Synopsis

Malicious Third Party Domain Detected

Description

Supply chain attacks occur when one or more dependencies of an application are compromised, making the malicious code being shipped to the web application and, allowing threat actors to perform various operations depending on the logic of the code being altered like credentials stealing or application backdooring.

Solution

Review each domain flagged in the plugin output and look for alternatives trusted sources if needed. If the dependency is not really used, remove it from your web application and conduct forensics operations to check if a previous compromission occured and mitigate it.

See Also

https://sansec.io/research/polyfill-supply-chain-attack

https://www.bleepingcomputer.com/news/security/polyfillio-bootcdn-bootcss-staticfile-attack-traced-to-1-operator/

Plugin Details

Severity: Medium

ID: 114358

Type: remote

Published: 7/3/2024

Updated: 7/3/2024

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Medium

Score: 5.2

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: Tenable

CVSS v3

Risk Factor: High

Base Score: 8.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

CVSS Score Source: Tenable

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L

CVSS Score Source: Tenable

Reference Information