 Pentest-Report Vitess 02.2019Bielefelder Str. 14 D 10709 Berlin cure53.de · mario@cure53.de • The cryptographic and authentication-related aspects were analyzed for potential general bypasses but no flaws allowing timing-safe variant of comparing strings. Using Go’s ConstantTimeCompare in the crypto/subtle’s module is advised. Cure53, Berlin · 03/08/19 7/9 Dr.-Ing. Mario0 码力 | 9 页 | 155.02 KB | 1 年前3 Pentest-Report Vitess 02.2019Bielefelder Str. 14 D 10709 Berlin cure53.de · mario@cure53.de • The cryptographic and authentication-related aspects were analyzed for potential general bypasses but no flaws allowing timing-safe variant of comparing strings. Using Go’s ConstantTimeCompare in the crypto/subtle’s module is advised. Cure53, Berlin · 03/08/19 7/9 Dr.-Ing. Mario0 码力 | 9 页 | 155.02 KB | 1 年前3
 Vitess security auditMissing documentation on deploying VTAdmin-web securely Moderate Yes 2 ADA-VIT-SA23-2 Insecure cryptographic primitives Informational Yes 3 ADA-VIT-SA23-3 SQL injection in sqlutils Informational Yes 4 length required for the actor name. 17 Vitess Security Audit, 2023 ADA-VIT-SA23-2: Insecure cryptographic primitives ID ADA-VIT-SA23-2 Component Multiple Severity Informational Fixed Yes Vitess uses that all uses of insecure hashing functions fall in one of two categories: they are either not cryptographic primitives or Vitess are bound to use a specific hashing algorithm to comply with MySQLʼs interface0 码力 | 41 页 | 1.10 MB | 1 年前3 Vitess security auditMissing documentation on deploying VTAdmin-web securely Moderate Yes 2 ADA-VIT-SA23-2 Insecure cryptographic primitives Informational Yes 3 ADA-VIT-SA23-3 SQL injection in sqlutils Informational Yes 4 length required for the actor name. 17 Vitess Security Audit, 2023 ADA-VIT-SA23-2: Insecure cryptographic primitives ID ADA-VIT-SA23-2 Component Multiple Severity Informational Fixed Yes Vitess uses that all uses of insecure hashing functions fall in one of two categories: they are either not cryptographic primitives or Vitess are bound to use a specific hashing algorithm to comply with MySQLʼs interface0 码力 | 41 页 | 1.10 MB | 1 年前3
 The Vitess 7.0 Documentation The Vitess 7.0 Documentation- ‘%v’: %v GetThrottlerConfiguration Returns the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be returned. Example - ‘%v’: %v UpdateThrottlerConfiguration Updates the configuration of the MaxReplicationLag module. The configuration must be specified as protobuf text. If a field is omitted or has a zero value - ‘%v’: %v ResetThrottlerConfiguration Resets the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be reset. Example 0 码力 | 254 页 | 949.63 KB | 1 年前3
 The Vitess 6.0 DocumentationUpdateThrottlerConfiguration GetThrottlerConfiguration Returns the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be returned. 126 Example The Vitess 6.0 DocumentationUpdateThrottlerConfiguration GetThrottlerConfiguration Returns the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be returned. 126 Example- ‘%v’: %v ResetThrottlerConfiguration Resets the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be reset. Example - ‘%v’: %v UpdateThrottlerConfiguration Updates the configuration of the MaxReplicationLag module. The configuration must be specified as protobuf text. If a field is omitted or has a zero value 0 码力 | 210 页 | 846.79 KB | 1 年前3
 The Vitess 5.0 DocumentationUpdateThrottlerConfiguration GetThrottlerConfiguration Returns the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be returned. 134 Example The Vitess 5.0 DocumentationUpdateThrottlerConfiguration GetThrottlerConfiguration Returns the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be returned. 134 Example- ‘%v’: %v ResetThrottlerConfiguration Resets the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be reset. Example - ‘%v’: %v UpdateThrottlerConfiguration Updates the configuration of the MaxReplicationLag module. The configuration must be specified as protobuf text. If a field is omitted or has a zero value 0 码力 | 206 页 | 875.06 KB | 1 年前3
 The Vitess 8.0 Documentation The Vitess 8.0 Documentation- ‘%v’: %v GetThrottlerConfiguration Returns the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be returned. Example - ‘%v’: %v UpdateThrottlerConfiguration Updates the configuration of the MaxReplicationLag module. The configuration must be specified as protobuf text. If a field is omitted or has a zero value - ‘%v’: %v ResetThrottlerConfiguration Resets the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be reset. Example 0 码力 | 331 页 | 1.35 MB | 1 年前3
 The Vitess 11.0 Documentation The Vitess 11.0 Documentation- ‘%v’: %v GetThrottlerConfiguration Returns the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be returned. Example - ‘%v’: %v UpdateThrottlerConfiguration Updates the configuration of the MaxReplicationLag module. The configuration must be specified as protobuf text. If a field is omitted or has a zero value - ‘%v’: %v ResetThrottlerConfiguration Resets the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be reset. Example 0 码力 | 481 页 | 3.14 MB | 1 年前3
 The Vitess 10.0 Documentation The Vitess 10.0 Documentation- ‘%v’: %v GetThrottlerConfiguration Returns the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be returned. Example - ‘%v’: %v UpdateThrottlerConfiguration Updates the configuration of the MaxReplicationLag module. The configuration must be specified as protobuf text. If a field is omitted or has a zero value - ‘%v’: %v ResetThrottlerConfiguration Resets the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be reset. Example 0 码力 | 455 页 | 3.07 MB | 1 年前3
 The Vitess 9.0 Documentation The Vitess 9.0 Documentation- ‘%v’: %v GetThrottlerConfiguration Returns the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be returned. Example - ‘%v’: %v UpdateThrottlerConfiguration Updates the configuration of the MaxReplicationLag module. The configuration must be specified as protobuf text. If a field is omitted or has a zero value - ‘%v’: %v ResetThrottlerConfiguration Resets the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be reset. Example 0 码力 | 417 页 | 2.96 MB | 1 年前3
 The Vitess 12.0 Documentation The Vitess 12.0 Documentation- ‘%v’: %v GetThrottlerConfiguration Returns the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be returned. Example - ‘%v’: %v UpdateThrottlerConfiguration Updates the configuration of the MaxReplicationLag module. The configuration must be specified as protobuf text. If a field is omitted or has a zero value - ‘%v’: %v ResetThrottlerConfiguration Resets the current configuration of the MaxReplicationLag module. If no throttler name is specified, the configuration of all throttlers will be reset. Example 0 码力 | 534 页 | 3.32 MB | 1 年前3
共 10 条
- 1













