Comprehensive Security Analysis and Threat Mitigation Strategies for React.js Applications: Leveraging SonarQube for Robust Security Assurance
Daniyal Murtaza, Razi Haider, Farhan Khan · 2024
React JS is one of the leading front-end technologies which has been manufactured by Facebook in 2013. It provides multiple pros to the developers including Virtual DOM, reusable interfaces, and separate refreshing of each component which exponentially harnesses the efficiency of a website. With these leverages, thousands of websites have already been built on React JS. According to Built with (A website that keeps track of websites built using a particular framework), 11,908,579 live websites are built on ReactJS. The goal of this paper is to help these huge numbers of websites by performing security analysis on the React JS open-source repository. This is because if React JS takes notice of these vulnerabilities by understanding the attack scenarios and mitigates them as per this paper then every website built on React JS will obtain advantages from it. For this purpose, SonarQube (a modern static analysis tool) has been utilized to perform analysis on React JS. Afterwards, the CVSS (Common Vulnerability Scoring System) is used to determine the severity levels of vulnerabilities. The vulnerabilities with the highest severity levels have been descriptively analyzed in separate sections with the aid of the CWE repository, OWASP cheat sheets, virtual patching, and secure design principles. To understand and mitigate such vulnerabilities, a set of attack scenarios and a mitigation plan have also been discussed to fix the code-base of React JS. In summary, the motivation is to analyze the React JS open-source repository through SonarQube and then perform a deep analysis of the potential vulnerabilities by first understanding attack scenarios and then mitigating them with the aid of the CWE repository, OWASP cheat sheets, virtual patching, and secure design principles.