codanalystブログ
すべての記事

この記事はまだ日本語に翻訳されていません。英語版を表示しています。

セキュリティ

Outdated JavaScript libraries: the vulnerability nobody looks at

An old version of jQuery or an abandoned plugin can be enough to expose your visitors. How to take inventory, update without breaking things and secure your CDNs.

C

Codanalyst チーム

3分で読めます

目次
  1. 01Why it's a real risk
  2. 02Take inventory
  3. 03Update without breaking everything
  4. 04Files loaded from a CDN
  5. 05Remove what you no longer use

A site can have an up-to-date server, a valid certificate and all the right security headers, and still be vulnerable because of a file that has been loaded for years without anyone thinking about it: an old version of jQuery, an abandoned carousel plugin, a charting library copied from a tutorial.

These files don't break anything, so they stay. And that's exactly the problem.

Why it's a real risk

Vulnerabilities in popular libraries are public. When one is discovered, it's recorded in databases such as the CVE list, along with the affected versions. An attacker then only needs to spot the version your site loads, often visible in the file name or its header, to know exactly which attack to try.

The most common vulnerabilities in these libraries are XSS flaws: they allow code to run in your visitors' browsers, for example to steal a session or alter a payment form.

Take inventory

First step: know what your site actually loads. In the browser's developer tools, Network tab, filter on "JS" and reload the page. For each file, note the library and its version.

If your project uses npm, the following command lists dependencies with known vulnerabilities:

npm audit

And this one, the packages that have a newer version available:

npm outdated

Update without breaking everything

Fear of regressions is the main reason updates get postponed. A few habits reduce it a lot:

  • update often, in small steps: going from one minor version to the next is rarely painful, catching up on five years of delay almost always is;
  • read the release notes before a major update, which flag breaking changes;
  • test the critical journeys after each update: contact form, cart, payment, login;
  • automate the monitoring with a tool like Dependabot or Renovate, which opens an update request as soon as a new version is released.

Files loaded from a CDN

Loading a library from a public CDN is convenient, but you're trusting a third-party server. If it were compromised, the file served to your visitors could be modified. The integrity attribute protects against this scenario: the browser checks the file's fingerprint and refuses to run it if it doesn't match.

<script
  src="https://cdn.jsdelivr.net/npm/example@2.4.1/dist/example.min.js"
  integrity="sha384-…fingerprint provided by the CDN…"
  crossorigin="anonymous"></script>

Always pin a precise version in the URL. A URL pointing to "the latest version" can change content overnight, and the fingerprint would no longer match.

Remove what you no longer use

The safest update is removal. A slider taken off the home page two years ago whose script is still loaded, an animation library used for a single effect: every file less is one less attack surface, and a faster page.

Codanalyst detects the JavaScript libraries loaded by your pages, identifies their version and flags those with known vulnerabilities. Check your site in a minute.

この記事は役に立ちましたか?

チームにも共有しましょう。

inX

今すぐ始める

サイトを診断してみませんか?

優先順位付きの完全なレポートを1分以内に。初回の診断は無料です。

  • 契約期間の縛りなし
  • クレジットカード不要
  • インストール不要