새로운 소식 – AWS Private Marketplace 다중 카탈로그 지원

2021-01-29 KENNETH 0

새로운 소식 – AWS Private Marketplace 다중 카탈로그 지원 AWS는 2014년에 AWS Marketplace를 출시했습니다. 고객은 이를 통해 Independent Software Vendor(ISV)에서 개발한 클라우드 기반 애플리케이션을 찾아 구매하고 즉시 사용할 수 있습니다. 2018년에는 Private Marketplace를 추가하여 기능을 보강했습니다. 이 기능을 통해 AWS Marketplace에서 사용자가 구매할 수 있는 승인된 제품 목록을 엄선하여 표시할 수 있습니다. 오늘 AWS는 AWS Organizations에서 Private Marketplace의 다중 카탈로그를 생성할 수 있도록 새 기능을 추가했습니다. 각 Private Marketplace는 서로 다른 제품 세트를 포함하여 특정 계정 그룹에 맞춤화된 경험을 제공할 수 있습니다. 다양한 사용자 그룹을 보유한 고객은 비즈니스 요구 사항에 맞게 거버넌스를 확장해야 합니다. 예를 들어, 서로 다른 산업에 자회사가 있는 대기업은 각 자회사에 대해 다양한 소프트웨어 요구 사항과 정책을 보유하고 있습니다. IT 관리자는 조직 전체에서 이러한 다양한 요구 사항을 해결하기 위해 조달 프로세스를 확장하는 데 어려움을 겪고 있으며, 전체 조직을 관리하기 위해 하나의 조달 정책으로 돌아가는 경우도 종종 있습니다. [ more… ]

No Image

USN-4707-1: TCMU vulnerability

2021-01-28 KENNETH 0

USN-4707-1: TCMU vulnerability It was discovered that TCMU lacked a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. Source: USN-4707-1: TCMU vulnerability

No Image

USN-4706-1: Ceph vulnerabilities

2021-01-28 KENNETH 0

USN-4706-1: Ceph vulnerabilities Olle Segerdahl found that ceph-mon and ceph-mgr daemons did not properly restrict access, resulting in gaining access to unauthorized resources. An authenticated user could use this vulnerability to modify the configuration and possibly conduct further attacks. (CVE-2020-10736) Adam Mohammed found that Ceph Object Gateway was vulnerable to HTTP header injection via a CORS ExposeHeader tag. An attacker could use this to gain access or cause a crash. (CVE-2020-10753) Ilya Dryomov found that Cephx authentication did not verify Ceph clients correctly and was then vulnerable to replay attacks in Nautilus. An attacker could use the Ceph cluster network to authenticate via a packet sniffer and perform actions. This issue is a reintroduction of CVE-2018-1128. (CVE-2020-25660) Source: USN-4706-1: Ceph vulnerabilities

No Image

USN-4709-1: Linux kernel vulnerabilities

2021-01-28 KENNETH 0

USN-4709-1: Linux kernel vulnerabilities It was discovered that the LIO SCSI target implementation in the Linux kernel performed insufficient identifier checking in certain XCOPY requests. An attacker with access to at least one LUN in a multiple backstore environment could use this to expose sensitive information or modify data. (CVE-2020-28374) Wen Xu discovered that the XFS filesystem implementation in the Linux kernel did not properly track inode validations. An attacker could use this to construct a malicious XFS image that, when mounted, could cause a denial of service (system crash). (CVE-2018-13093) It was discovered that the btrfs file system implementation in the Linux kernel did not properly validate file system metadata in some situations. An attacker could use this to construct a malicious btrfs image that, when mounted, could cause a denial of service (system crash). (CVE-2019-19813, CVE-2019-19816) Bodong Zhao [ more… ]

No Image

USN-4708-1: Linux kernel vulnerabilities

2021-01-28 KENNETH 0

USN-4708-1: Linux kernel vulnerabilities Wen Xu discovered that the XFS filesystem implementation in the Linux kernel did not properly track inode validations. An attacker could use this to construct a malicious XFS image that, when mounted, could cause a denial of service (system crash). (CVE-2018-13093) It was discovered that the btrfs file system implementation in the Linux kernel did not properly validate file system metadata in some situations. An attacker could use this to construct a malicious btrfs image that, when mounted, could cause a denial of service (system crash). (CVE-2019-19813, CVE-2019-19816) Bodong Zhao discovered a use-after-free in the Sun keyboard driver implementation in the Linux kernel. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2020-25669) Daniel Axtens discovered that PowerPC RTAS implementation in the Linux kernel did not properly restrict [ more… ]