Четвёртая часть цикла про свой удостоверяющий центр. В первой мы развернули Root CA и три промежуточных центра, во второй научились отзывать сертификаты и подняли OCSP-responder, в третьей настроили вход по клиентскому сертификату в nginx и Apache. Осталось ответить на вопрос, который…
Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is only exposed when the non-default trace level logging is enabled. Note: NGINX Agent is included with NGINX Instance Manager and used in conjunction with NGINX API Connectivity Manager, and NGINX Management Suite Security Monitoring.
Аудит дизайна сайта — это системный анализ его визуальной и функциональной составляющих, который помогает выявить ошибки, мешающие пользователям комфортно взаимодействовать с ресурсом. В этой статье разберём:- Что такое аудит дизайна и зачем он нужен?- Как провести аудит самостоятельно: пошаговая инструкция- Основные ошибки дизайна и способы их исправления- Инструменты для проверки юзабилити и визуальной привлекательности Читать далее
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Attackers can change the immutable name and type of nodes of InLong. Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick [1] to solve it. [1] https://cveprocess.apache.org/cve5/[1]%C2%A0https://github.com/apache/inlong/pull/7891 https://github.com/apache/inlong/pull/7891 https://github.com/apache/inlong/pull/7891