All articles| All Pictures| All Softwares| All Video| Go home page| Write articles| Upload pictures

Reading number is top 10 articles
曾经估值10亿美元,要做100年的印象笔记濒临倒闭 - 印象笔记,evernote
泰坦尼克号将在中国按1-1比例复原 - 博鳌亚洲论坛,泰坦尼克号
China’s “Hag“ foreigner crazy
上海警方销毁4000余组赌博游戏机 - 赌博游戏机
国庆节后丧心病狂的朋友圈状态都在这了 - 国庆节,朋友圈,十一假期
Ali sports will launch a competing platform, hosting the world esports games,
Visiting United States military secrets Smartphone project,
经老婆同意,周鸿祎拿出个人10%股份奖励核心员工 - 周鸿祎,360
Express nominal real-name system for the purposes of 4 months, big guns,
Police in Huizhou: e-rate loan 11 suspects arrested by the law,
Reading number is top 10 pictures
The money of more than 100 countries and regions13
A man's favorite things9
Beauty Sun Feifei
Distribution of wealth in China survey status report
Chinese paper-cut grilles art appreciation7
Players in the eyes of a perfect love2
Look for from human art net, is good1
Download software ranking
The Bermuda triangle3
Photoshop 8.0图象编辑软件
Love the forty days
Tram sex maniac 2 (H) rar bag12
Tram sex maniac 2 (H) rar bag15
Unix video tutorial8
Unix video tutorial17
Unix video tutorial19
published in(发表于) 2016/6/27 9:17:31 Edit(编辑)
High risk vulnerabilities are found, Java, PHP and NodeJS, Ruby development application or enrollment

High risk vulnerabilities are found, Java, PHP and NodeJS, Ruby development application or enrollment(高危漏洞被发现,Java、PHP、NodeJS、Ruby开发应用或中招)



High risk vulnerabilities are found, Java, PHP and NodeJS, Ruby development application or enrollment-vulnerability Java,OpenAPI-IT information

Information on IT recently, a widely exist in Java, PHP and NodeJS and popular languages such as Ruby application vulnerabilities were found that could exist in the OpenAPI (Swagger Code Generator), belonging to the parameter injection vulnerability, consolidating OpenAPI applications will be affected.

An attacker could use this vulnerability to Swagger plant malicious code in JSON files, remote execution. Worth noting is that the flaw has been disclosed as early as April 2016 details and repair patch, but does not seem to be enough Swagger defenders seriously, because they never answered it.

For security reasons, developers and technicians deploy bug fixes should be stepped up, and in order to eliminate the potential threat of the vulnerability as soon as possible.

高危漏洞被发现,Java、PHP、NodeJS、Ruby开发应用或中招 - 漏洞,Java,OpenAPI - IT资讯

IT资讯讯 近日,一个广泛存在于Java、PHP、NodeJS和Ruby等流行语言开发应用的漏洞被发现,该漏洞存在于OpenAPI(Swagger Code Generator)中,属于参数注入漏洞,凡是整合OpenAPI的应用都会受到影响。

攻击者可以利用该漏洞在Swagger JSON文件中植入恶意代码,实现远程执行。值得注意的是,该漏洞早在2016年4月就已经被披露过细节以及修复补丁,但似乎并没有受到Swagger维护者的足够重视,因为他们从未回应此事。


添加到 添加到新浪ViVi 添加到百度搜藏 添加到POCO网摘 添加到天天网摘365Key 添加到和讯网摘 添加到天极网摘 添加到黑米书签 添加到QQ书签 添加到雅虎收藏 添加到奇客发现 diigo it 添加到饭否 添加到飞豆订阅 添加到抓虾收藏 添加到鲜果订阅 digg it 貼到funP 添加到有道阅读 Live Favorites 添加到Newsvine 打印本页 用Email发送本页 在Facebook上分享

Disclaimer Privacy Policy About us Site Map

If you have any requirements, please contact webmaster。(如果有什么要求,请联系站长)
Copyright ©2011-, Inc. All rights reserved.