Security Advisory: High Severity Curl Vulnerability

The maintainers of curl, the popular command-line tool and library for transferring data with URLs, will release curl 8.4.0 on October 11, 2023. This version will include a fix for two common vulnerabilities and exposures (CVEs), one of which the curl maintainers rate as “HIGH” severity and described as “probably the worst curl security flaw in a long time.” 

The CVE IDs are: 

CVE-2023-38545: severity HIGH (affects both libcurl and the curl tool)

CVE-2023-38546: severity LOW (affects libcurl only, not the tool)

Specific details of the exploit have yet to be published. We expect these details to be published when the version update becomes available.

We will continue to update this blog post as more information becomes available.

In the meantime, you can prepare ahead of exploitability details being released on October 11 by using Docker Scout to check whether you’re using the curl library as a dependency in any of the container images in your organization.

Am I vulnerable?

We anticipate that any version of curl prior to 8.4.0 will be affected by these CVEs, so now is a good time to build up a list of what you’ll need to update on October 11, 2023.

Having a dependency on curl won’t necessarily mean the exploit will be possible for your application. When more details are published, Docker Scout will surface specifics about the exploitability of this vulnerability. The first step is to understand whether your images have a dependency on curl.  

Quickest way to assess all images 

The quickest way to assess all images is to enable Docker Scout for your container registry. 

Step 1: Enable Docker Scout

Docker Scout currently supports Docker Hub, JFrog Artifactory, and AWS Elastic Container Registry. Instructions for integrating Docker Scout with these container registries:

Integrating Docker Scout with Docker Hub

Integrating Docker Scout with JFrog Artifactory

Integrating Docker Scout with AWS Elastic Container Registry

Note: If your container registry isn’t supported right now, you’ll need to use the local evaluation method via the CLI, described later.

Step 2: Select the repositories you want to analyze and kick off an analysis

Docker Scout analyzes all local images by default, but to analyze images in remote repositories, you need to enable Docker Scout image analysis. You can do this from Docker Hub, the Docker Scout Dashboard, and CLI. Find out how in the overview guide.

Sign in to your Docker account with the docker login command or use the Sign in button in Docker Desktop.

Use the Docker CLI docker scout repo enable command to enable analysis on an existing repository:

$ docker scout repo enable –org <org-name> <org-name>/scout-demo

Step 3: Visit scout.docker.com 

On the scout.docker.com homepage, find the policy card called No vulnerable version of curl and select View details (Figure 1). 

Figure 1: Docker Scout dashboard with the policy card that will help identify if and where the vulnerable version of curl exists.

The resulting list contains all the images that violate this policy — that is, they contain a version of curl that is likely to be susceptible to the HIGH severity CVE (CVE-2023-38545) listed above.

Figure 2: Docker Scout showing list of images that violate the policy by containing affected versions of the curl library.

Alternative CLI method

An alternative method is to use the Docker Scout CLI to analyze and evaluate local container images.

You can use the docker scout policy command to evaluate images against Docker Scout’s built-in policies on the command line, including the No vulnerable version of curl. 

docker scout policy [IMAGE] –org [ORG]

Figure 3: Docker Scout showing the results of running the Docker Scout command to evaluate a container image against the ‘No vulnerable version of curl’ policy.

If you’d rather understand all the CVEs identified in an individual container image, you can run the following command. This method doesn’t require you to enable Docker Scout in your container registry but will take a little longer if you have a large number of images to analyze. 

docker scout cves [OPTIONS] [IMAGE|DIRECTORY|ARCHIVE]

Learn more

Follow direct updates from the maintainer of curl project via the GitHub issue.

Learn more about Docker Scout at docs.docker.com/scout.

Read Announcing Docker Scout GA: Actionable Insights for the Software Supply Chain.

Quelle: https://blog.docker.com/feed/

Managing Domains on WordPress.com Has Never Been Better

Your domain is the lifeblood of your online presence. For the last few months, we’ve been hard at work building a number of exciting features to ensure a world-class domain name experience on WordPress.com whether you have one domain or one hundred! 

Below, we highlight a handful of new enhancements in how you manage and organize your domains on our platform. 

Get your domain name today

Table of Contents

Table of ContentsA fresh look for your domains dashboardSecure your domain for the long term with multi-year registrationsAmplify your brand with domain (and subdomain) forwarding Easily transfer your domain to another WordPress.com user Bulk updates now available DNS imports made simpleReady to dive in?

A fresh look for your domains dashboard

One of the first things you’ll notice is the stunning visual overhaul of the domain management dashboard. We’ve made significant improvements to make it more intuitive and enjoyable, especially for those of you with multiple domains. 

Secure your domain for the long term with multi-year registrations

You can now secure your domain(s) for multiple years at a time, all the way up to ten years for most TLDs. Remember, you don’t need to have a website with WordPress.com to house your domain with us. 

Amplify your brand with domain (and subdomain) forwarding 

This feature is perfect for folks who want to utilize a unique domain name that will lead visitors to a specific site or page. Forwarding your domain or subdomain can be used for a number of purposes:

E-commerce Campaigns: Launching a product? Secure a catchy domain and point it directly to your product page.

Rebranding: If your long-established domain isn’t snappy, mask it with a more memorable one.

Social Media Simplification: Make it easy for people to find your Facebook or LinkedIn by redirecting a unique domain straight to your profile.

Learn more about domain forwarding. 

Easily transfer your domain to another WordPress.com user 

If you’re looking to transfer a domain to another WordPress.com user, there’s no need to reach out to our Happiness Engineers. Do it yourself with a single click from the transfer settings page.  

Learn more about domain transfers. 

Bulk updates now available 

We’ve made it easier than ever to manage multiple domains. With our latest update, you can now perform bulk updates, like setting auto-renewal options or updating your contact details. No more clicking through to individual domain management pages. 

DNS imports made simple

With every domain transferred to us, we attempt to discover and import your DNS records automatically to make sure your website, email, and other services continue working as expected after the domain transfer is complete. We also allow you to import all your DNS records using our new BIND file imports. Both those features are available to you to allow a smooth transfer of your domain. We still recommend all our users check and confirm all their DNS records were imported successfully to avoid any service interruptions.

Ready to dive in?

We can’t wait for you to try out these feature upgrades yourself. If you have domains with us already, visit your dashboard:

Manage your domain(s)

If you need a new domain, get started here: 

Get your domain name today

And if you have a domain to transfer from Google or Squarespace, we’ll cover the fees for you and provide an extra year of registration. Learn more and get started here. 

Thank you for choosing us as your trusted domain hosting provider. We’re excited to continue supporting your online journey and helping you make a lasting impact on the web.

Quelle: RedHat Stack

Introducing a New GenAI Stack: Streamlined AI/ML Integration Made Easy

At DockerCon 2023, with partners Neo4j, LangChain, and Ollama, we announced a new GenAI Stack. We have brought together the top technologies in the generative artificial intelligence (GenAI) space to build a solution that allows developers to deploy a full GenAI stack with only a few clicks.

Here’s what’s included in the new GenAI Stack:

1. Pre-configured LLMs: We provide preconfigured Large Language Models (LLMs), such as  Llama2, GPT-3.5, and GPT-4, to jumpstart your AI projects.

2. Ollama management: Ollama simplifies the local management of open source LLMs, making your AI development process smoother.

3. Neo4j as the default database: Neo4j serves as the default database, offering graph and native vector search capabilities. This helps uncover data patterns and relationships, ultimately enhancing the speed and accuracy of AI/ML models. Neo4j also serves as a long-term memory for these models.

4. Neo4j knowledge graphs: Neo4j knowledge graphs to ground LLMs for more precise GenAI predictions and outcomes.

5. LangChain orchestration: LangChain facilitates communication between the LLM, your application, and the database, along with a robust vector index. LangChain serves as a framework for developing applications powered by LLMs. This includes LangSmith, an exciting new way to debug, test, evaluate, and monitor your LLM applications.

6. Comprehensive support: To support your GenAI journey, we provide a range of helpful tools, code templates, how-to guides, and GenAI best practices. These resources ensure you have the guidance you need.

Figure 1: The GenAI Stack guide and access to the GenAI Stack components.

Conclusion

The GenAI Stack simplifies AI/ML integration, making it accessible to developers. Docker’s commitment to fostering innovation and collaboration means we’re excited to see the practical applications and solutions that will emerge from this ecosystem. Join us as we make AI/ML more accessible and straightforward for developers everywhere.

The GenAI Stack is available in Early Access now and is accessible from the Docker Desktop Learning Center or on GitHub. 

Participate in our Docker Docker AI/ML Hackathon to show off your most creative AI/ML solutions built on Docker. Read our blog post “Announcing Docker AI/ML Hackathon” to learn more.

At DockerCon 2023, Docker also announced its first AI-powered product, Docker AI. Sign up now for early access to Docker AI. 

Learn more

Find the GenAI Stack on GitHub.

Join the Docker Docker AI/ML Hackathon.

Sign up now for early access to Docker AI. 

Get the latest release of Docker Desktop.

Vote on what’s next! Check out our public roadmap.

Have questions? The Docker community is here to help.

New to Docker? Get started.

Quelle: https://blog.docker.com/feed/

Amazon Braket bietet jetzt Sichtbarkeit in Echtzeit für Warteschlangen von Quantenaufgaben und Hybridaufträgen

Amazon Braket ist ein vollständig verwalteter Service, mit dem Kunden ganz einfach in das Quantencomputing einsteigen können. Ab heute erhalten Kunden Sichtbarkeit in Echtzeit für die Länge der Geräte-Warteschlangen und die einzelnen Warteschlangenpositionen ihrer Quantenaufgaben und Hybridaufträge. Dadurch wird der Ausführungszeitpunkt ihrer Workloads transparenter.
Quelle: aws.amazon.com