Webhook URL is not allowed
ID |
unapproved_webhook |
Severity |
low |
Remediation Complexity |
trivial |
Remediation Risk |
medium |
Remediation Effort |
low |
Family |
CI/ CD Security |
Tags |
ASVS50:v12.1.1, ASVS50:v16.2.1, cicd-security, infrastructure, reachable, security, spvs10-v1.4.5, spvs10-v5.4.1 |
Description
A malicious actor may attempt to access the code permanently by implementing a webhook.
This detector performs an inventory of the webhooks invoked from SCM and CI/ CD systems and check them against a white list provided by the customer.
Security
After successfully compromising a user’s account, a malicious actor may attempt to access the code permanently by implementing a webhook