CISA’s secure-software buying tool had a simple XSS vulnerability of its own
Full article623 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
A researcher who discovered the vulnerability said it was fixed in December, after he first reported it to the agency in September.
Listen to this article
0:00
Learn more.
A Cybersecurity and Infrastructure Security Agency tool dedicated to helping government agencies buy secure software turned out to have a cybersecurity vulnerability of its own.
Jeff Williams, the former leader of the Open Worldwide Application Security Project (OWASP), told CyberScoop that he discovered a cross-site scripting vulnerability in CISA’s “Software Acquisition Guide: Supplier Response Web Tool” and reported it to CISA in September, before it was eventually fixed in December.
The vulnerability involves attackers injecting JavaScript into a web page, then getting that JavaScript to attack other users of that same page, he said. It also could have been used to deface the website, he said.
Williams, co-founder and chief technology officer of the application security firm Contrast Security, said it should have been easy for someone to spot the vulnerability at CISA, since it was the first attack he tried.
“I thought it was a little hypocritical to be promoting secure software development and not do the most basic test you could possibly do,” he said.
When Williams first reported the flaw through a bug bounty program, they rejected it as not critical enough, but he later got attention to the flaw from CISA’s Vulnerability Information and Coordination Environment program. The government shutdown contributed to the delay in fixing it, but Williams said it should’ve been just five minutes of work.
Williams said that while there are worse bugs than the one he uncovered, “I have customers that would treat this vulnerability as incredibly serious, because they take their reputation to be one of their most important assets.”
CISA’s role as an evangelist for cybersecurity hasn’t made it immune to cyberattacks. Notably, the agency identified a breach in 2024 that triggered a notification to Congress.
The chief information officer for CISA, Robert Costello, said the agency took action after receiving notification about a potential vulnerability.
“As per protocol, we addressed and patched the vulnerability, ensuring there was no significant risk or known exploitation,” he said in a statement to CyberScoop. “Additionally, our team identified process improvements for future vulnerabilities reported to the agency. As a champion for the CVE [Common Vulnerabilities and Exposures] program, CISA followed the standard coordinated disclosure processes to create a CVE that documents the vulnerability. CISA appreciates the report provided by this security researcher. This is another example of operational collaboration in action.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cisa-secure-software-buying-tool-had-a-simple-xss-vulnerability-of-its-own/