As further developments showed, this was precisely the first of the Apache Struts versions put forward, and the vulnerability (CVE-2017-5638) that affected Equifax customers was identified two months earlier by the US CERT team and a patch was released for it at about the same time, but Equifax network administrators never bothered to install it.
open source software for the large number of vulnerabilities would be reckless, since part of the responsibility lies with organizations that are unwilling to install security patches within a reasonable macedonia whatsapp data frame, especially in the case of critical bugs. It is possible that there are users who are unaware of which open source components interact with their systems and what update mechanism they use. The Equifax incident highlighted the importance of keeping systems up to date, but there are other open source bugs that companies for some reason fail to fix.
Another vulnerability that made a lot of noise was HeartBleed (CVE-2014-0160). This is a security vulnerability in the OpenSSL software library (an open implementation of the SSL/TLS encryption protocol), which allowed hackers to access the contents of the RAM of servers, which at that time could contain private data of users of various web services. OpenSSL acts as a standard open-source library for the Apache and NGINX web servers. According to the research company Netcraft, about 500 thousand websites could be affected by the CVE-2014-0160 vulnerability.
It should be noted that blaming
-
- Posts: 529
- Joined: Mon Dec 23, 2024 3:13 am