3. of Denial of Service II
An attacker can make a client unavailable or unusable but the problem goes away when the attacker stops (client, authenticated, temporary).
Threat |
|
You are using a third-party JavaScript library and an attacker changes the source code, a supply chain attack, to inject JavaScript code into your site, obliging clients to make multiple requests to his site which performs a slow read attack, forcing the client to read one byte at a time. |
|
CAPEC |
CAPEC-446 – Malicious logic insertion into the product via the inclusion of a third-party component |
ASVS |
10.1.1 – Ensure you’re scanning your code for vulnerabilities as part of your secure development process |
CWE |
CWE-74 – Improper... |