Description
Storing or executing downloaded scripts or plugins without verifying a hash, signature, or fixed trust chain may run modified code with the application's permissions.
Potential impact
- Network tampering or repository compromise may introduce malicious code.
- Persistent backdoors or arbitrary files may be installed in the deployment environment.
Remediation
- Verify the downloaded code's SHA-256 digest or digital signature.
- Prefer package managers, lockfiles, and signature verification over downloading code at runtime where possible.
Examples
Before
python
code = requests.get(url).text
exec(code)
After
python
data = requests.get(url, timeout=5).content
digest = hashlib.sha256(data).hexdigest()
if not hmac.compare_digest(digest, expected_digest):
raise ValueError("bad digest")
Explanation:
- Before: Downloaded scripts or plugins are executed without a verified hash, signature, or fixed trust chain. Network tampering, repository compromise, or DNS manipulation can introduce malicious code.
- After: The downloaded code's SHA-256 digest or signature is checked against a fixed, trusted value.