I published a blog post about six vulnerabilities in Git/GitHub-related projects. They all result in credential leakage when cloning a malicious repository, so be sure to update the Git installation!
flatt.tech/research/pos...
I published a blog post about six vulnerabilities in Git/GitHub-related projects. They all result in credential leakage when cloning a malicious repository, so be sure to update the Git installation!
flatt.tech/research/pos...
Thank you so much for reading it!
Thank you for reading it ;)
If you're interested in the technical details, I wrote the blog post here: flatt.tech/research/pos...
For the further details, please check out the announcement from the OpenWrt team: lists.openwrt.org/pipermail/op... (2/2)
[PSA]
If you're using OpenWrt router and have used the Attended sysupgrade, firmware-selector.openwrt[.]org or CLI upgrade previously, I recommend you to re-flash your firmware.
Due to a security issue, it was possible to pollute the firmware images delivered to these tools. (1/2)
OpenWrtใฎใใซใ็จใตใผใใผใซ่ๅผฑๆงใๅ ฑๅใใพใใใ
Attended sysupgradeใfirmware-selector.openwrt[.]orgใใใใฏCLIใใใฎใขใใใฐใฌใผใใ้ๅปใซๅฎๆฝใใๅ ดๅใๆนใใใใใใใกใผใ ใฆใงใขใ้
ไฟกใใใๅฏ่ฝๆงใๅฎๅ
จใซใฏๅฆๅฎใงใใชใใใใใใกใผใ ใฆใงใขใฎๅๆดๆฐใๆจๅฅจใใพใใ
ๆ่ก็่งฃ่ชฌใซใคใใฆใฏใใกใใฎ่จไบใใ็ขบ่ชใใ ใใใ flatt.tech/research/pos...
ๅ
ฌๅผใใใฎ็บ่กจใฏใใกใใใ่ฆงใใ ใใใ lists.openwrt.org/pipermail/op...
ใใฎใใกใใ: BlueskyใจTwitterใฎ่ชๅใในใ
ใญใ
ใญใใฑใฃใฑ
Blueskyใใพใ ใใงใใฌใผใทใงใณใงใใชใใฎใ
Dynamicใชๆณข
UnstableใชTableใฏใใชใๅซใ ใช
StableใชTable
ใชใคใธใฎใฃใฐ็ณปใจใณใธใใขใงใใใจใใใฎ @ryotak.net
@ryotak.net ใใ ใใถTwitterใ ใชใใ
@ryotak.net ใใใ ใใถTwitterใใฎใ๏พ๏พ๏ฝฒ๏พ๏พ๏พใใฎ้จๅใ
ใ ใใถTwitterใฎๅคงไปใฎ้จๅ by RyotaK
ใใใใใญใฆใใใใฏ้ชๆชใฎๆชใง
็ฌ่ชใใกใคใณใจใท๏ผ