The OWASP 2013 Top 10 introduced a new item: A9 - Use of components with known vulnerabilities.
While many known vulnerabilities cause only minor impacts, some of the biggest security breaches have been exploited through dependencies (third-party components) in applications. Depending on the assets you are protecting, mitigating this risk should be a priority.
All organizations should ensure that there is an ongoing plan for monitoring, screening, and applying updates or configuration changes throughout the application's lifecycle or across the entire portfolio. Fortunately, this task can be automated.
In this video, André Kanagusku (Architect on the Digital Architecture team at Santander) shows us how to identify vulnerabilities in dependencies in an automated way, using Dependency-Check*.
*According to OWASP (Open Web Application Security Project), Dependency-Check has strategic value for the application security discipline.
It's worth mentioning that Dependency-Check is a free, open-source tool.
Check it out! If you like it, please like the video, subscribe to the channel to receive future content, and don't forget to share it with your team. Until next time!
• Segurança de software - Vulnerabilidades e...