CAPEC™ 445: Malicious Logic Insertion into Product Software via Configuration Management Manipulation
Description
An adversary exploits a configuration management system so that malicious logic is inserted into a software products build, update or deployed environment. If an adversary can control the elements included in a product's configuration management for build they can potentially replace, modify or insert code files containing malicious logic. If an adversary can control elements of a product's ongoing operational configuration management baseline they can potentially force clients receiving updates from the system to install insecure software when receiving updates from the server.
Source: CAPEC™ 445
Related ASVS Requirements
ASVS (5.0): 13.2.3, 13.3.1, 13.3.2, 13.3.3, 13.3.4, 15.1.1, 15.1.2, 15.2.1, 15.2.4, 15.2.5, 16.3.4