Curated articles, resources, tips and trends from the DevOps World.
Summary: This is a summary of an article originally published by the source. Read the full original article here →
by Cisco has released a set of patches for their Data Center Network Manager (DCNM), a platform for managing Cisco data centers.
An attacker could exploit this vulnerability by using the static key to craft a valid session token.
Embarrassingly enough, in the beginning of this year Cisco already patched one issue that involved static API key in DCNM.
Matt Keil, Director of Product Marketing at Cequence Security, sheds light on the API-side of this latter leak: “Data Viper, a purported security company, lost its database as a result of poor API secure coding practices – the developer left their credentials exposed in an API usage document.
Made with pure grit © 2024 Jetpack Labs Inc. All rights reserved. www.jetpacklabs.com