Research

Posts from the Veracode security research team that zero in a bit on new ideas, trends, and technology. The content here will help deepen your understanding of various application security topics and satisfy the technically-inclined reader.

Fixing Vulnerabilities with Safe Versions

asharma's picture
By Asankhaya Sharma May 23, 2016

Last week Vanessa gave a presentation about the security risks associated with using open source libraries at the Null Singapore Meetup. There was a great discussion afterwards talking through different approaches people had for mitigating these risks. Unfortunately, it's a bit more complicated than just updating your project dependencies. Safe Versions When a vulnerability is disclosed,... READ MORE

TLS Verification in Ruby Client Libraries

jyeo's picture
By Jason Yeo April 10, 2016

A week ago, a couple of security researchers warned about unverified TLS certificates in SSL libraries of some programming languages. You may read more at their blog. In summary, they found that all programming languages do not verify revoked certificates and languages like Python and PHP do not verify certificates in some cases. That is, if you are using Python or PHP to make HTTPS requests, you... READ MORE

Administrate Vulnerability Disclosure

jyeo's picture
By Jason Yeo March 31, 2016

Last week, I found a CSRF vulnerability in the Administrate gem. The controllers that are generated by the gem do not enforce CSRF protection. As we saw in the previous post, the CSRF protection mechanism in Rails can fail you if you are not careful in ensuring that your callbacks are idempotent to prevent session memoization. In addition, as Rails developers we don't simply work with our own... READ MORE

Handlebars.js Vulnerability Impact Study

vhenderson's picture
By Vanessa Henderson January 31, 2016

A few weeks ago, I described a cross-site scripting vulnerability in the popular handlebars.js library in my blog post here. A number of other JavaScript libraries and applications were also affected because of copy-and-pasted code and a tendency for developers to include and distribute the JavaScript source files directly in their projects. After following our responsbile disclosure policy and... READ MORE

Answering your questions about the new State of Software Security report

TJarrett's picture
By Tim Jarrett December 7, 2015  | Research

state-of-software-security-focus-on-application-development-1.jpg On December 3, Veracode published a new supplemental State of Software Security Report, Focus on Application Development. As you might have guessed, the report has raised comments and questions – particularly about the security of applications written in different programming languages. There have been some... READ MORE

Cut-and-paste component vulnerabilities - A short study of how a handlebars.js vulnerability has spread

vhenderson's picture
By Vanessa Henderson December 6, 2015

Today, we are going to explore a cross-site scripting vulnerability in the popular handlebars library. The handlebars library provides a logicless templating language that enables you to separate the view and the rest of your code. This library is based off of the popular mustache templating language modified by Yehuda Katz, also known as wycats on GitHub. Over 9,000 people have starred... READ MORE

Commons Collections Deserialization Vulnerability Research Findings

cfenton's picture
By Caleb Fenton December 1, 2015

A few weeks ago, I wrote about the recent Apache Commons Collections deserialization vulnerability in Let’s Calm Down About Apache Commons Collections. I said we were going to look into finding other libraries that were also vulnerable. In this post, I publish the findings and conclusions. Then I geek-out by excitedly describing plans and ideas for future research. Research Method The original... READ MORE

Amazon AWS Java SDK Vulnerability Disclosure

asharma's picture
By Asankhaya Sharma November 23, 2015

Last week, we disclosed a CSRF-style vulnerability in Spring Social Core to Pivotal. Today, we will talk about a denial of service vulnerability in the Amazon AWS SDK for Java. This official AWS SDK is used by Java developers to integrate with various AWS services including interaction with the Amazon APIs for storing and retrieving files from S3 buckets. The releases 1.8.0 to 1.10.34 of the AWS... READ MORE

Spring Social Core Vulnerability Disclosure

pambrosini's picture
By Paul Ambrosini November 11, 2015

Today we would like to announce the discovery of a vulnerability in the Spring Social Core library. Spring Social provides Java bindings to popular service provider APIs like GitHub, Facebook, Twitter, etc., and is widely used by developers. All current versions (1.0.0.RELEASE to 1.1.2.RELEASE) of the library are affected by this vulnerability. To exploit this vulnerability, an attacker can... READ MORE

Security Headers on the Top 1,000,000 Websites: November 2015 Report

IDawson's picture
By Isaac Dawson November 3, 2015  | Research

It has been over a year since the last analysis on security headers was run. The current state of security header usage will be presented along with a differential analysis of the previous run from October 2014. While no architectural changes to the scanner were made this time, this will be the last run done with this code base.  A new scanner is currently under development to gain more... READ MORE

Love to learn about Application Security?

Get all the latest news, tips and articles delivered right to your inbox.

 

 

 

contact menu