Web Security

Vulnerable Components

Risk: Using components with known vulnerabilities. Demonstrates outdated libraries, insecure deserialization, and dependency management.

WEB-VULN-01Module ID
Hands-onLab Type
IntermediateLevel

Overview

Manage risk from dependencies by tracking SBOMs, scanning for CVEs, and safely upgrading or mitigating issues.

Learning Outcomes

  • Build and maintain SBOMs for apps
  • Automate dependency and container scanning
  • Understand insecure deserialization patterns
  • Apply SemVer-aware update strategies
  • Monitor advisories and backport fixes

Hands-on Labs

Create SBOMs, scan dependencies, and remediate or mitigate with configuration.

Operations

Governance for third-party risk: allowlists, pinning, and runtime protections.