Thứ Tư, Tháng Hai 8, 2023
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
No Result
View All Result
Home Tech

Hackers start serious exploits

21 Tháng Mười, 2022
in Tech
0
Hackers start serious exploits
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter

Các bài viết liên quan:

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022

Apache Commons Text Vulnerability

Security company WordPress Wordfence on Thursday said it began detecting exploit attempts against a newly disclosed vulnerability in Apache Commons Text on October 18, 2022.

The vulnerability, tracked as CVE-2022-42889 aka Text4Shell, has been given a severity rating of 9.8 out of 10.0 possible on the CVSS scale and affects versions 1.5 to 1.9 of the library.

It is similar to today’s well-known Log4Shell vulnerability in that the problem stems from the way string substitutions are performed during DNS, script and URL lookups that can lead to arbitrary code execution on other sites. The system is sensitive to unreliable input transfers.

Successful exploitation of this vulnerability could allow an attacker to open connection as opposed to a simple vulnerable application through a specially crafted payload, effectively opening the door to further attacks.

Although the problem was initially reported in early March 2022, the Apache Software Foundation (ASF) released an updated version of the software (1.10.0) on September 24, then issued advice only last week on October 13.

“Fortunately, not all users of this library are affected by this vulnerability – unlike Log4J in the Log4Shell vulnerability, this vulnerability is vulnerable even in basic use cases. best,” said Checkmarx researcher Yaniv Nizry.

“Apache Commons Text must be used in a certain way to expose an attack and make the vulnerability open to exploitation.”

Wordfence also reiterates that the likelihood of successful exploits is significantly limited in scope compared to Log4j, with most of the payloads observed to date designed to scan vulnerable installations.

“A successful attempt would result in the victim site making a DNS query to an attacker-controlled listening domain,” said Wordfence researcher Ram Gall.

If anything, this development is yet another indication of the potential security risks posed by third-party open source dependencies, requiring organizations to regularly assess the attack surface. their own and establish appropriate patch management strategies.

Users who directly depend on Apache Commons Text are recommended to upgrade to the fixed version to mitigate potential threats. According to the Maven Repository, there are 2,593 projects using the Apache Commons Text library.

The Apache Commons Text vulnerability also follows another critical security vulnerability that was disclosed in Apache Commons Configuration in July 2022 (CVE-2022-33980, CVSS score: 9.8), which could lead to implementation execute arbitrary code through variable interpolation function.

Related Posts

Previous Post

Download Autodesk ArtCAM 2018 Full Crack

Next Post

50+ Best Men’s Short Layered Hairstyles

Megusta

Megusta

Related Posts

5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
Instruction how to use OBS streaming software

Features, settings and how to use OBS streaming software through 9 simple steps

25 Tháng Mười Hai, 2022
What is Trans woman?  What is Transgender Women?

What is Trans woman? What is Transgender Women?

23 Tháng Mười Hai, 2022
Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

22 Tháng Mười Hai, 2022
How to get 50 free coins of SkyJoy App to redeem

How to get 50 free coins of SkyJoy App to redeem

21 Tháng Mười Hai, 2022
Load More
Next Post
50+ Best Men’s Short Layered Hairstyles

50+ Best Men's Short Layered Hairstyles

Trả lời Hủy

Email của bạn sẽ không được hiển thị công khai. Các trường bắt buộc được đánh dấu *

Bài viết mới

How to get travel insurance
Đời sống

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly
Phần mềm

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games
Software

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power
Software

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 
Tech

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software
Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022
W3Schools

Ads

Contact: [email protected]

DMCA.com Protection Status

Categories

  • Android
  • Cạm bẫy tâm lí
  • Chưa được phân loại
  • Đồ họa
  • Đời sống
  • Gen Z
  • Health
  • iOS
  • Kĩ năng mềm
  • News
  • Nhà mạng
  • Phần mềm
  • Phần mềm đồ họa
  • Review sách
  • Software
  • Tech
  • Thiết kế ảnh
  • Thiết kế video
  • Thủ thuật
  • Travel
  • Văn hóa Nam Bộ
  • Văn học
  • Window

Browse by Tag

ai là triệu phú android Apple browser Bullet Journal bản thân chai pin Chỉnh ảnh data domain download fshare game game show giả lập màu hosting IKEA ios khuyến mãi kinh doanh kiến thức kiểm tra pin messenger miễn phí mua sắm Máy ảnh mạng network nghệ thuật ngôn ngữ nhà Trần pin laptop quảng cáo tiếng anh trạng thái Trần Thủ Độ tên miền tắt hoạt động từ vựng video viettel window 10 word zalo Đơn giản

Recent News

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023

Trang tin nóng hổi - vừa thổi vừa xem

No Result
View All Result
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z

Trang tin nóng hổi - vừa thổi vừa xem