Apache Druid Remote Code Execution Vulnerability Notice

Overview Recently, NSFOCUS CERT found that an Apache Druid remote code execution vulnerability was publicly disclosed online. Under default configuration, Apache Druid supports loading data from Kafka. Unauthenticated remote attackers can implement JNDI injection attacks by modifying Kafka connection configuration properties, ultimately leading to the execution of arbitrary code on...

Google Chrome Skia Integer Overflow Vulnerability (CVS 2023-2136) Notice

Overview Recently, NSFOCUS CERT found that Google officially fixed an integer overflow vulnerability in Chrome Skia (CVE-2023-2136). Due to a flaw in Skia, when the value exceeds the maximum limit of integer type due to arithmetic operations, an integer overflow will occur. The attacker triggers this vulnerability by inducing users...

Looking Forward to Seeing You at RSAC 2023

Moscone Center, South Hall, Booth # 4301 - San Francisco, CA, United States We are exhibiting at RSA Conference 2023. This is a great opportunity for you to network with cybersecurity’s forward-thinking global community and explore innovative, new technology. Connect with NSFOCUS executives and security experts to discuss how to manage unexpected risks...

Apache Solr Remote Code Execution Vulnerability (CNVD-2023-27598) Notice

Overview Recently, NSFOCUS CERT found that the analysis article of Apache Solr remote code execution vulnerability was publicly disclosed on the Internet. When Solr is launched in cloud mode and can go offline, an unauthenticated remote attacker can execute arbitrary code on the target system by sending multiple specially crafted...