<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnerability-Management on krash.dev</title><link>https://krash.dev/tags/vulnerability-management/</link><description>Recent content in Vulnerability-Management on krash.dev</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 14 Aug 2026 08:29:09 +0530</lastBuildDate><atom:link href="https://krash.dev/tags/vulnerability-management/rss.xml" rel="self" type="application/rss+xml"/><item><title>Investigating Reported Vulnerabilities: A Closer Look!</title><link>https://krash.dev/posts/investigating-reported-vulnerability/</link><pubDate>Sun, 30 Jul 2023 00:00:00 +0000</pubDate><guid>https://krash.dev/posts/investigating-reported-vulnerability/</guid><description>&lt;p&gt;In vulnerability scanners or penetration testing reports, you might come across statements like &lt;em&gt;&amp;ldquo;Service version x.y.z is vulnerable to CVE-YYYY-ABCD.&amp;rdquo;&lt;/em&gt; However, it&amp;rsquo;s essential to delve deeper to confirm the actual vulnerability.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s consider a real example:&lt;/p&gt;
&lt;p&gt;We received a vulnerability report indicating a vulnerability (&lt;a href="https://curl.se/docs/CVE-2023-23916.html" target="_blank" rel="noopener noreferrer"&gt;CVE-2023-23916&lt;/a&gt;) in curl v7.74.0 within the Debian 11 environment.&lt;/p&gt;
&lt;p&gt;The CVE documentation mentions:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;Affected versions: curl 7.57.0 to and including 7.87.0&lt;/p&gt;
&lt;/blockquote&gt;&lt;p&gt;At first glance, it appears that v7.74.0 is indeed vulnerable. But is that really the case?&lt;/p&gt;</description></item><item><title>NULLCON 2021 Training: DEVSECOPS</title><link>https://krash.dev/posts/nullcon-2021-training-devsecops/</link><pubDate>Sat, 27 Mar 2021 00:00:00 +0000</pubDate><guid>https://krash.dev/posts/nullcon-2021-training-devsecops/</guid><description>&lt;p&gt;You don’t need money to buy expensive things, sometimes hard work pays off. And yes nullcon trainings are still expensive for me xD and I am grateful that I got this chance to attend one.&lt;/p&gt;
&lt;p&gt;One year ago, I was going through the nullcon training schedule, and trying to understand the structure, and how much I can learn from it, because it was too expensive for me to get the actual training. Cut to March 1st , 2021, where I was attending a nullcon Training called – “&lt;a href="https://nullcon.net/website/goa-2021/training/DevSecOps-automating-security-in-devops.php" target="_blank" rel="noopener noreferrer"&gt;DEVSECOPS – AUTOMATING SECURITY IN DEVOPS&lt;/a&gt; by Rohit Salecha”, not only as an attendee but also as a moderator for the event, because I was the one of the employees at &lt;a href="https://payatu.com/" target="_blank" rel="noopener noreferrer"&gt;Payatu&lt;/a&gt;.&lt;/p&gt;</description></item></channel></rss>