Vulnerable and Outdated Components
Highlights the dangers of using software libraries, frameworks, or components that contain known vulnerabilities or are outdated. When applications rely on these components, they inherit their security weaknesses which could happen even server-side or client-side.
Here is a typical example of this vulnerability as follows:
The Log4Shell vulnerability is one of the most known examples of this. Is a vulnerability from the JavaScript library Log4J which allowed RCE and information disclosure
This has been fixed in the latest versions of Log4J, but the vulnerability will remain in every application using a non-outdated version of the library
Last updated
Was this helpful?