Quantcast
Channel: Security Boulevard
Viewing all articles
Browse latest Browse all 37364

CVE-2012-3586: Basho Riak API, Security Alert

$
0
0
On June 14th a comment on Github asked Basho about validation in their API The riak http api for map reduce doesn't check if the content-type is application/json. The javascript http api also lets the user execute arbitrary code on the server. These two coupled together allow a malicious web page to execute arbitrary code [...]

[[ This is a summary only. Read more at flyingpenguin.com ]]



Viewing all articles
Browse latest Browse all 37364

Trending Articles