T08 · Insecure Dependencies
- Location
template.html:393- Finding
Third-Party CDN Resources Loaded Without Subresource Integrity
- Content
View full analysis
``` ```html ``` ### Technical Analysis The generated HTML loads Bootstrap CSS, Bootstrap Icons, and executable Bootstrap JavaScript directly from jsDelivr. Although explicit package versions are used, the elements do not include Subresource Integrity (`integrity`) metadata. The document also does not define a restrictive Content Security Policy. Version pinning prevents routine upgrades from silently changing the requested package version, but it does not cryptographically verify the bytes returned to the browser. If the CDN, its delivery infrastructure, or the hosted artifact were compromised, altered JavaScript could execute whenever a generated document is opened while online. The remote stylesheet and icon resources also create supply-chain and availability dependencies. They can affect document presentation and cause the viewer's browser to disclose normal request metadata, including its IP address and user-agent string, to the external CDN. ### Attack Path 1. An attacker compromises the CDN delivery path, hosted artifact, or another component capable of changing the response for the pinned Bootstrap URL. 2. A user generates or copies a document based on `template.html`. 3. The user opens the generated HTML document while connected to the Internet. 4. The browser downloads `bootstrap.bundle.min.js` from jsDelivr without validating an expected cryptographic diges ...[truncated 1298 chars]- Remediation
View remediation
``` Replace the placeholder values only with hashes calculated or published for the exact referenced resources. 3. **Remove unnecessary executable dependencies** - The template does not visibly depend on Bootstrap JavaScript interactions. - If no dropdown, modal, collapse, tooltip, or similar component is required, remove the external script entirely. 4. **Deploy a restrictive Content Security Policy** - When documents are served over HTTP, define a CSP that limits scripts, styles, images, and network destinations to explicitly approved sources. - Avoid allowing `unsafe-inline` for scripts. - Where practical, move inline CSS to a local stylesheet so `style-src` can also be hardened. 5. **Support genuinely offline output** - Bundle all required fonts, icons, stylesheets, and scripts locally. - Document the reviewed dependency versions and establish a controlled process for future dependency updates. ]]>
