Stephen F. Austin State University
Managing Software Dependency Risks in Web Applications
Abstract
dc:description.abstract<p>Web applications commonly rely on third-party software dependencies to reduce development time. This thesis examines how vulnerabilities in a dependency chain propagate to compromise an application. It analyzes two vulnerable Markdown libraries from the npm and Composer dependency ecosystems, both of which are used for managing packages in applications developed with JavaScript and PHP. The analysis demonstrates how each library’s sanitizing functions—intended for removing unsafe user input when transforming Markdown text to HTML—are defeated to achieve a cross-site scripting exploit and take control of the application. The paper discusses potential business impacts of a compromise, underscoring the need for security improvements, and it presents strategies for mitigating dependency related vulnerabilities. These solutions focus on package management tools available to developers, and they advocate implementing emerging security standards as part of the development life cycle.</p>
Degree
thesis:*- Name thesis:degree_name
- Master of Science – Cyber Security
- Level thesis:degree_level
- Thesis
- Discipline thesis:degree_discipline
- College of Science and Mathematics
- Year dc:date.available
- 2025
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Scott, Christopher Alan
- Contributors dc:contributor
-
- Christopher Ivancic
- Pushkar Ogale
- Nikki Shoemaker
Subjects
dc:subject × 7Identifiers
dc:identifier.*- Repository record dc:identifier
- https://scholarworks.sfasu.edu/etds/610
- OAI identifier oai:identifier
- oai:scholarworks.sfasu.edu:etds-1644