The Apache Software Foundation (ASF) has released a new report examining key metrics, specific vulnerabilities and top security issues across its projects last year. The new report also notes all of the major security events that posed risks to its projects. According to the report, t he first serious security event last year was an issue in Tomcat, CVE-2020-1938 that was later named “Ghostcat,” which affected Tomcat installations that exposed an unprotected AJP Connector to untrusted networks. Now, various proof-of-concept exploits are public for this issue, including a Metasploit exploit. In May, the The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2017-5638, the remote command execution (RCE) vulnerability in Apache Struts 2 disclosed and fixed in 2017 to the list of Top 10 Routinely Exploited Vulnerabilities list. In July, versions of Apache Guacamole 1.1.0 were found to be vulnerable to issues in RDP, notably when a user connected to a malicious or compr
This website is about programming knowledge. You can call this blog best programming master.