#漏洞 RCE via unsafe inline Kramdown options when rendering certain Wiki pages
https://hackerone.com/reports/1125425
https://hackerone.com/reports/1125425
HackerOne
GitLab disclosed on HackerOne: RCE via unsafe inline Kramdown...
### Summary
When rendering wiki content with certain extensions such as `.rmd`, `render_wiki_content` will call...
When rendering wiki content with certain extensions such as `.rmd`, `render_wiki_content` will call...
#漏洞 cisco RV34X系列身份绕过和远程命令执行漏洞(CVE-2021-1472 CVE-2021-1473)
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-authentication-bypass-remote-command-execution/
https://www.iot-inspector.com/blog/advisory-cisco-rv34x-authentication-bypass-remote-command-execution/
#漏洞 Remote code execution in Homebrew by compromising the official Cask repository
https://blog.ryotak.me/post/homebrew-security-incident-en/
https://blog.ryotak.me/post/homebrew-security-incident-en/
blog.ryotak.net
Remote code execution in Homebrew by compromising the official Cask repository
この記事は日本語でも投稿されています: https://blog.ryotak.net/post/homebrew-security-incident/
(もし日本語が読める場合、筆者は英語がそこまで得意ではないため、日本語の記事を読むことをお勧めします。)
(Official blog post about this incident is available here: https://brew.sh/2021/04/21/security-incident-disclosure/)
Preface…
(もし日本語が読める場合、筆者は英語がそこまで得意ではないため、日本語の記事を読むことをお勧めします。)
(Official blog post about this incident is available here: https://brew.sh/2021/04/21/security-incident-disclosure/)
Preface…
#漏洞 Exploit CVE-2021-25735: Kubernetes Validating Admission Webhook Bypass
https://github.com/darryk10/CVE-2021-25735
https://github.com/darryk10/CVE-2021-25735
GitHub
GitHub - darryk10/CVE-2021-25735: Exploit CVE-2021-25735: Kubernetes Validating Admission Webhook Bypass
Exploit CVE-2021-25735: Kubernetes Validating Admission Webhook Bypass - darryk10/CVE-2021-25735
#漏洞 Apache Druid CVE-2021-26919 漏洞分析
http://m0d9.me/2021/04/21/Apache-Druid-CVE-2021-26919-%E6%BC%8F%E6%B4%9E%E5%88%86%E6%9E%90/
http://m0d9.me/2021/04/21/Apache-Druid-CVE-2021-26919-%E6%BC%8F%E6%B4%9E%E5%88%86%E6%9E%90/
m0d9's blog
Apache Druid CVE-2021-26919 漏洞分析
CVE-2021-26919是一个jdbc 反序列化类型漏洞,用作之前两篇jdbc mysql学习的练手,分析分析。 背景已知是jdbc mysql反序列化的问题,可以直接看看官方的修复 https://github.com/apache/druid/compare/druid-0.20.1...druid-0.20.2 具体在这个commit里https://github.com/apache/
#漏洞 宏电 H8922 路由器中多个漏洞(CVE-2021-28149~52)
https://ssd-disclosure.com/ssd-advisory-hongdian-h8922-multiple-vulnerabilities/
https://ssd-disclosure.com/ssd-advisory-hongdian-h8922-multiple-vulnerabilities/
SSD Secure Disclosure
SSD Advisory – Hongdian H8922 Multiple Vulnerabilities - SSD Secure Disclosure
TL;DR Find out how multiple vulnerabilities in Hongdian H8922 allow an attacker to run arbitrary commands on the device with root privileges as well as access the device with root privileges via a backdoor account. Vulnerability Summary The H8922 “4G industrial…
#漏洞 Webmin 多个高危漏洞(CVE-2021-31760~62)
CVE-2021-31760:
https://github.com/electronicbots/CVE-2021-31760
CVE-2021-31761:
https://github.com/electronicbots/CVE-2021-31761
CVE-2021-31762:
https://github.com/electronicbots/CVE-2021-31762
CVE-2021-31760:
https://github.com/electronicbots/CVE-2021-31760
CVE-2021-31761:
https://github.com/electronicbots/CVE-2021-31761
CVE-2021-31762:
https://github.com/electronicbots/CVE-2021-31762
GitHub
GitHub - electronicbots/CVE-2021-31760: Exploiting a Cross-site request forgery (CSRF) attack to get a Remote Command Execution…
Exploiting a Cross-site request forgery (CSRF) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature - GitHub - electronicbots/CVE-2021-31760: Exploiti...
#漏洞 Kubernetes 准入机制绕过(CVE-2021-25735)
https://sysdig.com/blog/cve-2021-25735-kubernetes-admission-bypass/
https://sysdig.com/blog/cve-2021-25735-kubernetes-admission-bypass/