OWASP / OWASP/Top10

Polyfill as an example of Supply Chain attack

Open
#812 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

2021
Dominant language
HTML
Stars
6.1k
Forks
1.1k
PR merge metrics
No merged PRs in 30d

Description

Hi there,

I was thinking, for the next edition of the OWASP (2025?) a good example of Supply Chain attack could be the polyfill.io incident.

It's a good example of why not to trust 3rd party CDNs, especially considering how widespread it got, affecting over 100k websites across the world.
And it was the result of a popular domain expiring and being acquired by a malicious party.

A good place to place this would be in the "Software and Data Integrity Failures" chapter, probably together with (or in lieu of) the SolarWinds Orion attack:
https://github.com/OWASP/Top10/blob/90859c5178d4208e1ebed5b481898b575b4b98ec/2021/docs/en/A08_2021-Software_and_Data_Integrity_Failures.md?plain=1#L70-L71

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review docs/en/A08_2021-Software_and_Data_Integrity_Failures.md, especially the section linked in the issue, and compare the existing SolarWinds Orion example with the proposed polyfill.io incident. Done means the chapter reflects a decided example choice and includes the relevant supply-chain incident context.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.