Response truly lived up to the insane rating, and was quite masterfully crafted. To start, I’ll construct a HTTP proxy that can abuse an SSRF vulnerability and a HMAC digest oracle to proxy traffic into the inner network and a chat application. With access as guest, I’ll find bob is eager to talk to the admin. I’ll redirect the LDAP auth to my host, where my LDAP server will grant access as admin, and I can talk to bob. bob speaks of an FTP server and gives creds, but I can’t access i...| 0xdf hacks stuff
runC, a container runtime component, published version 1.1.12 to fix CVE-2024-21626 at 31, Jan 2024, which leads to escaping from containers. The range of affected versions are >= v1.0.0-rc93, <=1.1.11. For containerd the fixed versions are 1.6.28 and 1.7.13, the range of affected versions are 1.4.7 to 1.6.27 and 1.7.0 to 1.7.12. For Docker the fixed version is 25.0.2. RepdoruceMy environment to repdouce it is: Linux distro: Arch Linux Linux kernel: 6.| Nitro's Blog
CVE Modified by CVE 11/21/2024 3:54:45 AM| nvd.nist.gov
Try TeamCity - the powerful Continuous Integration and Deployment tool for Developers and DevOps Engineers.| JetBrains
Our Vulnerability Research team discovered a critical vulnerability in the popular CI/CD server TeamCity, which attackers could use to steal source code and poison build artifacts.| www.sonarsource.com
CVE Modified by JetBrains s.r.o. 12/16/2024 7:15:04 AM| nvd.nist.gov