-
CVE-2019-12439 Project Atomic Bubblewrap bubblewrap.c Arbitrary Code Execution Vulnerability – MAy 2019
Preface: With sandbox technology, Security DevOps team might have easy to conduct test. Since the user can specify exactly what parts of the filesystem should be visible in the sandbox. Technical Background: The introduction of user namespaces in the Linux kernel has opened the doors to running containers as default user logins via e.g. ssh…
-
When the Chinese mythology Shan Hai Jing 《山海經》meets aliens.
Preface: In ancient China, there was not only ancient times. Before ancient times, there was a ancient era that we could difficult to explore. With regard to the myth book of China, because of the many legends and myths left. It let me tirelessly exploring. Background of the Shan Hai Jing: Shan Hai Jing《山海經》, Chinese…
-
CVE-2019-0188 Apache Camel XML External Entity Injection Vulnerability – May 2019
Preface: The computing market trending on open source development and thus its growth rapidly. Believe it or not, see how many Apache server running now. Apache Camel background: You can use MQ (message queues) to enable applications to communicate at different times and in many diverse computing environments. This is the famous vendor proprietary toys…
-
Previous vulnerabilities, today’s emergency alert – 1st June 2019
Preface: If the victim of cybersecurity is a defensive device? What you can do? Background: Leading players in the Global It Asset Management (Itam) Software Market Research Report are: HP, Cherwell Software, Oracle & Dell KACE . Vulnerability details: The Dell Kace K1000 Appliance contains multiple vulnerabilities, including a blind SQL injection vulnerability and a…