
ISC StormCast for Wednesday, April 26th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
00:00
How to Fix a Vulnerability in Apache Super Set
The Apache Super Set software that allows you to sort of visualize and explore data apparently comes with a pre-configure secret key. Horizon 3 AI now has a proof of concept exploit how this particular vulnerability can actually lead to a remote code execution on affected servers. The real problem here is that we have all of these reflectors out there just like we had these problems with DNS reflectors and other protocols like NTP and such.
Transcript
Play full episode