-
hiccup, web server load balancing solution 3rd May 2022
Preface: Online banking cannot lack of load balancing solution today. However in terms of life cycle of operation system and software libaries , Java language development platform and on-demand custom fuctions. Does it bother the load balancing functions? The most challenging parts is the layer 7 load balancing. Perhaps you can do the healt check…
-
About CVE-2022-28197: NVIDIA Jetson Linux Driver Package design weakness (26-4-2022)
Preface: Embedded AI solutions on the Linux platform. With the superior performance, small size and low power consumption, it will be able to do more real-time processing at the demanding environment than ever before. Background: NVIDIA® Jetson Nano™ Developer Kit is a small, powerful computer that lets you run multiple neural networks in parallel for…
-
Redis vulnerabilities – Lua readonly tables (CVE-2022-24736, CVE-2022-24735) – 27th April 2022
Preface: Complex data queries not to use Redis as a Database.Big data and the new phenomenon open data are closely related but they’re not the same. Open data is information that is available to the public, regardless of its intended purpose. Background: Redis is designed to be accessed by trusted clients inside trusted environments. This…
-
Big data perspective , CVE-2022-24706: Apache CouchDB Remote Privilege Escalation (26th April 2022)
Preface: NoSQL is used for Big data and real-time web apps. Perhaps if you can manage big data, you can rule the AI zone in future. Background: NoSQL is used for Big data and real-time web apps. For example, companies like Twitter, Facebook and Google collect terabytes of user data every single day. There are…
-
CVE-2022-29078 EJS package Security Focus (25th April 2022)
Preface: EJS is one of the most popular template engines for JavaScript. One of the reasons to choose it is that EJS code looks like pure HTML. Background: EJS or Embedded Javascript Templating is a templating engine used by Node. js. The template engine helps to create an HTML template with minimal code. Also, it…
-
About CVE-2022-29582 (asynchronous I/O interface provided by Linux kernelbefore 5.17.3)
Preface: On 29th March, 2022 Linus Torvalds announced the release and general availability of Linux 5.17 as the latest and greatest kernel series for Linux-based operating systems adding new features and improving hardware support. Background: As HPC workflows become more complex, data management services need to perform asynchronous I/O operations in the background. In addition,…
-
CVE-2022-23711 A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source (21st Apr, 2022)
Preface: According to market survey, there are 3723 companies reportedly use Elasticsearch in their tech stacks, including Uber, Shopify, and Udemy. Perhaps part of the 3723 companies will use Kibana at the same time. Background: As suggested by Elasticsearch, customers can install Kibana on the same server as Elasticsearch. But that’s not the only setup…
-
CVE-2022-29527 – Hiccups, AWS amazon-ssm-agent sudoer File default permission (20th April 2022)
Preface: Security misconfiguration vulnerabilities take place when an application component is vulnerable to attack as a result of insecure configuration option or misconfiguration. Background: AWS Systems Manager (formerly known as SSM) is Amazon software that runs on Amazon Elastic Compute Cloud (Amazon EC2) instances, edge devices, and on-premises servers and virtual machines (VMs). A managed…
-
CVE-2022-24826 – Git LFS can execute a binary from the current directory on Windows (19th April 2022)
Preface: In medium to small size firm, software developer is busy to achieve their company objective. Perhaps cyber security is not the priority of their awareness. The software version control is major successful factor of their software development. Perhaps they will make use of Git LFS (Large File Storage). Background: What is a git LFS?…
-
CVE-2022-28893 – Sun Microsystem not appear any more, however sunrpc still working on Linux. (14th April 2022)
Preface: ONTAP or Data ONTAP or Clustered Data ONTAP or Data ONTAP 7-Mode is NetApp’s proprietary operating system used in storage disk arrays such as NetApp FAS and AFF, ONTAP Select and Cloud Volumes ONTAP. RHEL 6.3 and later can be used with NetApp Clustered Data ONTAP. This setup integrate with SUNPRC UNIX Network Programming.Remark:…