{"id":8541,"date":"2016-06-26T00:02:59","date_gmt":"2016-06-25T15:02:59","guid":{"rendered":"http:\/\/begi.net\/news\/?p=8541"},"modified":"2016-06-26T00:06:44","modified_gmt":"2016-06-25T15:06:44","slug":"rapid7%e3%80%81api%e3%83%95%e3%83%ac%e3%83%bc%e3%83%a0%e3%83%af%e3%83%bc%e3%82%af%e3%80%8cswagger%e3%80%8d%e3%81%ab%e6%b7%b1%e5%88%bb%e3%81%aa%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ae%e5%ad%98%e5%9c%a8","status":"publish","type":"post","link":"https:\/\/begi.net\/news\/archives\/8541.html","title":{"rendered":"Rapid7\u3001API\u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u300cSwagger\u300d\u306b\u6df1\u523b\u306a\u8106\u5f31\u6027\u306e\u5b58\u5728\u3092\u767a\u8868"},"content":{"rendered":"<p><A HREF=\"https:\/\/www.rapid7.com\/\">Rapid7<\/A>\u306f6\u670822\u65e5(\u73fe\u5730\u6642\u9593)\u3001\u30aa\u30fc\u30d7\u30f3\u30bd\u30fc\u30b9\u306eAPI\u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u300cSwagger\u300d\u306b\u6df1\u523b\u306a\u8106\u5f31\u6027(CVE-2016-5641)\u304c\u767a\u898b\u3055\u308c\u305f\u3068\u767a\u8868\u3057\u305f\u3002<\/p>\n<p>\u8106\u5f31\u6027\u306f\u3001NodeJS\u3001PHP\u3001Ruby\u3001Java\u306a\u3069\u306eSwagger\u30b3\u30fc\u30c9\u30b8\u30a7\u30cd\u30ec\u30fc\u30bf\u306b\u5b58\u5728\u3059\u308b\u3068\u3044\u3046\u3002\u8106\u5f31\u6027\u306e\u5185\u5bb9\u306f\u3001\u60aa\u8cea\u306aSwagger\u5b9a\u7fa9\u306e\u5371\u967a\u3092\u8003\u616e\u3057\u3066\u3044\u306a\u3044\u3053\u3068\u306b\u3088\u308b\u3082\u306e\u3067\u3001\u60aa\u610f\u306e\u3042\u308bSwagger\u6587\u66f8\u3092\u5229\u7528\u3059\u308b\u3053\u3068\u306b\u3088\u3063\u3066\u30ea\u30e2\u30fc\u30c8\u304b\u3089\u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3055\u308c\u3066\u3057\u307e\u3046\u6050\u308c\u304c\u3042\u308b\u3068\u3044\u3046\u3002<\/p>\n<p>Rapid7\u306f\u3001\u30b3\u30fc\u30c9\u30b8\u30a7\u30cd\u30ec\u30fc\u30bf\u306e\u30d1\u30c3\u30c1\u304c\u516c\u958b\u3055\u308c\u308b\u307e\u3067\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u304cSwagger\u6587\u66f8\u3092\u53b3\u91cd\u306b\u30c1\u30a7\u30c3\u30af\u3059\u308b\u5fc5\u8981\u304c\u3042\u308b\u3068\u3057\u3066\u3044\u308b\u3002<\/p>\n<p align=\"right\">(\u5ddd\u539f \u9f8d\u4eba\/\u3073\u304e\u306d\u3063\u3068)<\/p>\n<p><b>[\u95a2\u9023\u30ea\u30f3\u30af]<\/b><br \/>\n<A HREF=\"https:\/\/community.rapid7.com\/community\/infosec\/blog\/2016\/06\/23\/r7-2016-06-remote-code-execution-via-swagger-parameter-injection-cve-2016-5641\">Blog\u306b\u3088\u308b\u8a18\u4e8b<\/A><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Rapid7\u306f6\u670822\u65e5(\u73fe\u5730\u6642\u9593)\u3001\u30aa\u30fc\u30d7\u30f3\u30bd\u30fc\u30b9\u306eAPI\u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u300cSwagger\u300d\u306b\u6df1\u523b\u306a\u8106\u5f31\u6027(CVE-2016-5641)\u304c\u767a\u898b\u3055\u308c\u305f\u3068\u767a\u8868\u3057\u305f\u3002 \u8106\u5f31\u6027\u306f\u3001NodeJS\u3001PHP\u3001Ruby\u3001Java\u306a\u3069\u306eS [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[],"class_list":["post-8541","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/begi.net\/news\/wp-json\/wp\/v2\/posts\/8541","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/begi.net\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/begi.net\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/begi.net\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/begi.net\/news\/wp-json\/wp\/v2\/comments?post=8541"}],"version-history":[{"count":5,"href":"https:\/\/begi.net\/news\/wp-json\/wp\/v2\/posts\/8541\/revisions"}],"predecessor-version":[{"id":8548,"href":"https:\/\/begi.net\/news\/wp-json\/wp\/v2\/posts\/8541\/revisions\/8548"}],"wp:attachment":[{"href":"https:\/\/begi.net\/news\/wp-json\/wp\/v2\/media?parent=8541"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/begi.net\/news\/wp-json\/wp\/v2\/categories?post=8541"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/begi.net\/news\/wp-json\/wp\/v2\/tags?post=8541"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}