-
Notifications
You must be signed in to change notification settings - Fork 13
Expand file tree
/
Copy pathdrupal-vulnerable-components.mdc
More file actions
103 lines (87 loc) · 6.08 KB
/
Copy pathdrupal-vulnerable-components.mdc
File metadata and controls
103 lines (87 loc) · 6.08 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
---
description: Detect and prevent vulnerabilities related to outdated or vulnerable components in Drupal as defined in OWASP Top 10:2021-A06
globs: *.php, *.install, *.module, *.inc, *.theme, *.yml, *.info
alwaysApply: false
---
# Drupal Vulnerable and Outdated Components Standards (OWASP A06:2021)
This rule enforces security best practices to prevent vulnerabilities related to outdated or vulnerable components in Drupal applications, as defined in OWASP Top 10:2021-A06.
## Rule Details
- **Name:** drupal_vulnerable_components
- **Description:** Detect and prevent vulnerabilities related to outdated or vulnerable components in Drupal as defined in OWASP Top 10:2021-A06
## Filters
- file extension pattern: `\\.(php|inc|module|install|info\\.yml|json)$`
- file path pattern: `.*`
## Enforcement Checks
- Conditions:
- pattern `core:\\s*('|\")8\\.[0-6](mdc:'|\")|core_version_requirement:\\s*('|\")[^9].+('|\")` – Potentially outdated Drupal core version detected. Consider upgrading to the latest secure version of Drupal 9 or 10.
- Pattern 1: Outdated Drupal core version declaration
- pattern `drupal_set_message\\(|format_date\\(|drupal_render\\(|entity_load\\(|variable_get\\(|variable_set\\(` – Deprecated function detected. Use modern replacements to ensure compatibility and security updates.
- Pattern 2: Usage of deprecated functions
- pattern `jquery\\.min\\.js\\?v=1\\.|jquery-1\\.|jquery-2\\.|ckeditor/|tinymce/|angular\\.js@1\\.` – Potentially vulnerable JavaScript library version detected. Update to the latest secure version.
- Pattern 3: Known vulnerable libraries referenced
- pattern `<script\\s+src=['\"]http|<script\\s+src=['\"]//|<link\\s+[^>]*href=['\"]http` – External scripts or stylesheets without Subresource Integrity (SRI) checks detected. Add integrity and crossorigin attributes.
- Pattern 4: Direct inclusion of external scripts without SRI
- pattern `module:\\s*('[^']*captcha'|'recaptcha'|'xmlrpc'|'openid'|'php')` – Potentially vulnerable or deprecated module detected. Consider using more secure alternatives.
- Pattern 5: Use of obsolete or removed modules
- pattern `\"drupal/[^\"]+\":\\s*\"(~|\\^)?[0-9]\\.[0-9]\\.[0-9]\"` – Hard-coded specific version detected in composer.json. Consider using version ranges to receive security updates.
- Pattern 6: Hard-coded versions in composer.json
- pattern `mysql_|split\\(|ereg\\(|eregi\\(|create_function\\(|each\\(` – Deprecated or insecure PHP function detected. Use modern alternatives for better security.
- Pattern 7: Outdated or insecure PHP API usage
- pattern `type:\\s*module\\s*\\nname:` – Ensure your module specifies core_version_requirement to prevent installation on unsupported Drupal versions.
- Pattern 8: Usage of contrib modules without version constraints
- pattern `composer\\.json` – Consider adding drupal/core-security-advisories as a dev dependency to detect known vulnerable packages.
- Pattern 9: Missing security advisories handling in composer.json
- pattern `check_plain\\(|filter_xss\\(|filter_xss_admin\\(` – Legacy text sanitization function detected. Use Html::escape() or Xss::filter() instead.
- Pattern 10: Direct usage of vulnerable sanitization functions
## Suggestions
- Guidance:
**Drupal Component Security Best Practices:**
1. **Update Management:**
- Keep Drupal core updated to the latest secure version
- Subscribe to the Drupal Security Newsletter
- Implement a regular update schedule (monthly at minimum)
- Use security advisories checking in your development workflow
- Implement Composer's security-advisories metadata
2. **Dependency Management:**
- Use Composer for managing all dependencies
- Specify version constraints that allow security updates
- Add drupal/core-security-advisories as a dev dependency
- Regularly run `composer update --with-dependencies`
- Use `composer outdated` to identify outdated packages
3. **API Usage:**
- Use modern Drupal APIs rather than deprecated functions
- Migrate away from jQuery to modern JavaScript where possible
- Implement Subresource Integrity (SRI) for external resources
- Update custom code to use current best practices
- Follow the Drupal API deprecation policies
4. **Security Monitoring:**
- Implement automated vulnerability scanning in CI/CD
- Use tools like Drupal Check or Upgrade Status module
- Monitor the Drupal security advisories page
- Implement automated updates for non-critical dependencies
- Set up alerts for security issues in used components
5. **Module Management:**
- Remove unused modules from your codebase
- Prefer well-maintained modules with security teams
- Implement proper version constraints in module info files
- Consider the security impact before adding new dependencies
- Document your dependency management practices
## Validation Checks
- Conditions:
- pattern `core_version_requirement:\\s*[\"']\\^(8\\.8|8\\.9|9|10)\\.[0-9]+[\"']` – Using proper core version requirements.
- Check 1: Proper core version requirement
- pattern `\\\\Drupal::messenger\\(\\)|->messenger\\(\\)|\\\\Drupal::service\\('messenger'\\)` – Using modern message API instead of deprecated functions.
- Check 2: Use of modern APIs
- pattern `\"require\":\\s*\\{[^}]*\"drupal/core(-recommended)?\":\\s*\"\\^[0-9]+\\.[0-9]+\"` – Using proper version constraints in Composer.
- Check 3: Proper composer usage
- pattern `integrity=[\"'][a-zA-Z0-9\\+/=\\-_]+[\"']\\s+crossorigin=[\"']anonymous[\"']` – Properly implementing Subresource Integrity.
- Check 4: SRI implementation
## Metadata
- Priority: high
- Version: 1.1
- Tags: security, drupal, dependencies, vulnerable-components, owasp, language:php, framework:drupal, category:security, subcategory:dependencies, standard:owasp-top10, risk:a06-vulnerable-components
## References
- https://owasp.org/Top10/A06_2021-Vulnerable_and_Outdated_Components/
- https://www.drupal.org/docs/security-in-drupal/staying-up-to-date
- https://www.drupal.org/docs/upgrading-drupal
- https://www.drupal.org/docs/develop/using-composer/managing-dependencies-for-a-drupal-project