Pentest-Report Vitess 02.2019it is by any means possible to inject API commands. The overarching goal was clearly to achieve injection of the OS-level commands. The filter implemented for this particular endpoint protects the function name. • The monitor and debug web interfaces were analyzed for common vulnerabilities like SQL injection or XSS. However, in all encountered cases the user-input was found to be correctly sanitized, in endpoints were tested for potential input manipulation, i.e. path traversal and OS-level command injection were attempted for every function that interacted with the file system. Cure53, Berlin · 03/08/190 码力 | 9 页 | 155.02 KB | 1 年前3
Vitess security auditYes 2 ADA-VIT-SA23-2 Insecure cryptographic primitives Informational Yes 3 ADA-VIT-SA23-3 SQL injection in sqlutils Informational Yes 4 ADA-VIT-SA23-4 Path traversal in VtctldServers GetBackups method ADA-VIT-SA23-3: SQL injection in sqlutils ID ADA-VIT-SA23-3 Component sqlutils Severity Informational Fixed in: https://github.com/vitessio/vitess/pull/12929 The sqlutils package contains an SQL Injection vulnerability0 码力 | 41 页 | 1.10 MB | 1 年前3
The Vitess 8.0 Documentationcluster’s metric is only as accurate as the following metrics: • The probe interval • The heartbeat injection interval • The aggregation interval The error margin equals approximately the sum of the above0 码力 | 331 页 | 1.35 MB | 1 年前3
The Vitess 9.0 Documentationcluster’s metric is only as accurate as the following metrics: • The probe interval • The heartbeat injection interval • The aggregation interval The error margin equals approximately the sum of the above0 码力 | 417 页 | 2.96 MB | 1 年前3
The Vitess 11.0 Documentationcluster’s metric is only as accurate as the following metrics: • The probe interval • The heartbeat injection interval • The aggregation interval The error margin equals approximately the sum of the above0 码力 | 481 页 | 3.14 MB | 1 年前3
The Vitess 10.0 Documentation
cluster’s metric is only as accurate as the following metrics: • The probe interval • The heartbeat injection interval • The aggregation interval The error margin equals approximately the sum of the above0 码力 | 455 页 | 3.07 MB | 1 年前3
The Vitess 12.0 Documentationcluster’s metric is only as accurate as the following metrics: • The probe interval • The heartbeat injection interval • The aggregation interval The error margin equals approximately the sum of the above0 码力 | 534 页 | 3.32 MB | 1 年前3
共 7 条
- 1













