Nova Trauben

Nova Trauben

Nova Trauben is a software developer at Veracode with a keen interest in open-source software security. They are a part of the SCA vulnerability curation team, enabling you to keep your use of open-source software secure!

Stay up to date on Application Security

Posts by Nova Trauben
  • Veracode Customers Shielded from NVD…
    | By Nova Trauben

    The US National Institute of Standards and Technology (NIST) has almost completely stopped analyzing new vulnerabilities (CVEs) listed in its National Vulnerability Database (NVD). Through the first six weeks of 2024, NIST analyzed over 3,500 CVEs with only 34 CVEs awaiting analysis.1 Since…

    Read Article
     
  • Resolving Webp Zero-day Vulnerability…
    | By Nova Trauben

    Executive Summary The webp image library is vulnerable to Heap Buffer Overflow. The exact steps to exploit the vulnerability have not been disclosed publicly. The NSO group was actively caring out a campaign which infected Apple devices with spyware, which was disclosed by Citizen Lab. It was later…

    Read Article
     
  • Resolving CVE-2022-1471  with the…
    | By Nova Trauben

    In October of 2022, a critical flaw was found in the SnakeYAML package, which allowed an attacker to benefit from remote code execution by sending malicious YAML content and this content being deserialized by the constructor. Finally, in February 2023, the SnakeYAML 2.0 release was pushed that…

    Read Article