{"id":93156,"date":"2020-09-03T19:42:00","date_gmt":"2020-09-03T17:42:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimosti-v-skanerah-bezopasnosti-obrazov-docker-kontejnerov"},"modified":"2020-09-03T19:42:00","modified_gmt":"2020-09-03T17:42:00","slug":"uyazvimosti-v-skanerah-bezopasnosti-obrazov-docker-kontejnerov","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-skanerah-bezopasnosti-obrazov-docker-kontejnerov","title":{"rendered":"Vulnerabilidades en esc\u00e1neres de seguridad para im\u00e1genes de contenedores Docker","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/medium.com\/@matuzg\/testing-docker-cve-scanners-part-2-5-exploiting-cve-scanners-b37766f73005\">Publicado<\/a><\/noindex> resultados de las pruebas de herramientas para detectar vulnerabilidades no corregidas y problemas de seguridad en im\u00e1genes de contenedores aislados de Docker. La verificaci\u00f3n mostr\u00f3 que en 4 de 6 esc\u00e1neres de im\u00e1genes de Docker conocidos hab\u00eda vulnerabilidades cr\u00edticas que permit\u00edan atacar directamente al esc\u00e1ner y lograr la ejecuci\u00f3n de su c\u00f3digo en el sistema, en algunos casos (por ejemplo, al usar Snyk) con privilegios de root. <\/p>\n<p>Para llevar a cabo el ataque, el atacante solo necesita iniciar una verificaci\u00f3n de su Dockerfile o manifest.json, que incluya metadatos especialmente dise\u00f1ados, o colocar archivos Podfile y gradlew dentro de la imagen. Se prepararon prototipos de exploits <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gmatuz\/cve-scanner-exploiting-pocs\">para sistemas<\/a><\/noindex> Fossa<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/www.whitesourcesoftware.com\/whitesource-for-containers\/\">WhiteSource<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/hub.docker.com\/r\/snyk\/snyk-cli\">Snyk<\/a><\/noindex>,<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/hub.docker.com\/r\/fossa\/fossa-cli\">. El paquete que mostr\u00f3 la mejor seguridad fue<\/a><\/noindex> y<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/hub.docker.com\/u\/anchore\">Anchore<\/a><\/noindex>, dise\u00f1ado originalmente con un enfoque en la seguridad. No se detectaron problemas en el paquete <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/quay\/clair\">Clair<\/a><\/noindex>. En conclusi\u00f3n, se lleg\u00f3 a la recomendaci\u00f3n de que los esc\u00e1neres de contenedores de Docker deben ejecutarse en entornos aislados o utilizarse solo para verificar sus propias im\u00e1genes, y tener precauci\u00f3n al conectar estas herramientas a sistemas automatizados de integraci\u00f3n continua. <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/aquasecurity\/trivy\">Trivy<\/a><\/noindex>En FOSSA, Snyk y WhiteSource, la vulnerabilidad estaba relacionada con la llamada a un gestor de paquetes externo para determinar las dependencias y permit\u00eda organizar la ejecuci\u00f3n de su c\u00f3digo a trav\u00e9s de los comandos touch y system en los archivos<\/p>\n<p>gradlew <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gmatuz\/cve-scanner-exploiting-pocs\/tree\/master\/snyk\/gradle\">Podfile<\/a><\/noindex> y <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gmatuz\/cve-scanner-exploiting-pocs\/tree\/master\/fossa\/cocoa\">En Snyk y WhiteSource tambi\u00e9n se<\/a><\/noindex>.<\/p>\n<p>encontraron <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gmatuz\/cve-scanner-exploiting-pocs\/tree\/master\/whitesource\/pip\">con la organizaci\u00f3n de la ejecuci\u00f3n de comandos del sistema al analizar el Dockerfile (por ejemplo, en Snyk a trav\u00e9s del Dockerfile se pod\u00eda reemplazar la utilidad \/bin\/ls que el esc\u00e1ner llama, y en WhiteSource se pod\u00eda inyectar c\u00f3digo a trav\u00e9s de argumentos en la forma \u00abecho \u2018;touch \/tmp\/hacked_whitesource_pip;=1.0\u2019\u00bb).<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gmatuz\/cve-scanner-exploiting-pocs\/tree\/master\/snyk\/docker\">una vulnerabilidad<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gmatuz\/cve-scanner-exploiting-pocs\/tree\/master\/whitesource\/generic\">relacionados<\/a><\/noindex> con la organizaci\u00f3n de la ejecuci\u00f3n de comandos del sistema al analizar el Dockerfile (por ejemplo, en Snyk, se pod\u00eda reemplazar la utilidad \/bin\/ls llamada por el esc\u00e1ner, y en WhiteSource, se pod\u00eda insertar c\u00f3digo a trav\u00e9s de argumentos en la forma &#171;echo  &#8216;;touch \/tmp\/hacked_whitesource_pip;=1.0&#8242;&#187;). <\/p>\n<p>fue provocada <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gmatuz\/cve-scanner-exploiting-pocs\/tree\/master\/anchore\">por el uso de la utilidad<\/a><\/noindex> skopeo <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/containers\/skopeo\">para trabajar con im\u00e1genes de docker. La explotaci\u00f3n consist\u00eda en agregar al archivo manifest.json par\u00e1metros como \u2018\u00bbos\u00bb: \u00ab$(touch hacked_anchore)\u00bb\u2018, que se inyectan al llamar a skopeo sin el adecuado escape (solo se eliminaban los caracteres \u00ab;&amp;\u00bb, pero se permit\u00eda la construcci\u00f3n \u00ab$()\u00bb).<\/a><\/noindex> para trabajar con im\u00e1genes de docker. La explotaci\u00f3n se limitaba a agregar en el archivo manifest.json par\u00e1metros del tipo &#8216;&#187;os&#187;: &#171;$(touch hacked_anchore)&#187;&#8216;, que se insertan al invocar skopeo sin el debido escape (solo se eliminaban los caracteres &#171;;&#038;&lt;&gt;&#187;, pero se admit\u00eda la construcci\u00f3n &#171;$()&#187;).<\/p>\n<p>El mismo autor llev\u00f3 a cabo un estudio sobre la efectividad de la detecci\u00f3n de vulnerabilidades no corregidas por esc\u00e1neres de seguridad de contenedores Docker y el nivel de falsos positivos (<noindex><a rel=\"nofollow\" href=\"https:\/\/medium.com\/@matuzg\/testing-docker-cve-scanners-part-1-false-negatives-and-what-they-mean-for-your-security-77fc4eb1b2cf\">parte 1<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/medium.com\/@matuzg\/testing-docker-cve-scanners-part-2-how-good-is-package-detection-f68d7230b830\">parte 2<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/medium.com\/@matuzg\/testing-docker-cve-scanners-part-3-test-it-yourself-conclusions-6de868124d3d\">parte 3<\/a><\/noindex>). A continuaci\u00f3n se muestran los resultados de las pruebas de 73 im\u00e1genes que contienen vulnerabilidades conocidas, as\u00ed como una evaluaci\u00f3n de la efectividad para detectar aplicaciones est\u00e1ndar en las im\u00e1genes (nginx, tomcat, haproxy, gunicorn, redis, ruby, node).<\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/miro.medium.com\/max\/840\/1*4CS8SAbix-domsIWNgrk5A.png\"><img decoding=\"async\" alt=\"Vulnerabilidades en esc\u00e1neres de seguridad para im\u00e1genes de contenedores Docker \" src=\"\/wp-content\/uploads\/2020\/09\/001d442a6b6467583ca1668b68fdc81f.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/miro.medium.com\/max\/840\/1*Xxbob0nabha6N6ZBfBuSLg.png\"><img decoding=\"async\" alt=\"Vulnerabilidades en esc\u00e1neres de seguridad para im\u00e1genes de contenedores Docker \" src=\"\/wp-content\/uploads\/2020\/09\/eb765e141efe5d22954742eb0cc1470e.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53650\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u044f \u043d\u0435\u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0438 \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0441 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c\u044e \u0432 \u043e\u0431\u0440\u0430\u0437\u0430\u0445 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043e\u0432 Docker. \u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u043f\u043e\u043a\u0430\u0437\u0430\u043b\u0430, \u0447\u0442\u043e \u0432 4 \u0438\u0437 6 \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u0445 \u0441\u043a\u0430\u043d\u0435\u0440\u043e\u0432 \u043e\u0431\u0440\u0430\u0437\u043e\u0432 Docker \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u043e\u0432\u0430\u043b\u0438 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0438\u0435 \u0430\u0442\u0430\u043a\u043e\u0432\u0430\u0442\u044c \u043d\u0435\u043f\u043e\u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0435\u043d\u043d\u043e \u0441\u0430\u043c \u0441\u043a\u0430\u043d\u0435\u0440 \u0438 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435, \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u0441\u043b\u0443\u0447\u0430\u044f\u0445 (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u043f\u0440\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0438 Snyk) \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root. \u0414\u043b\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":93157,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-93156","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u044f.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-skanerah-bezopasnosti-obrazov-docker-kontejnerov\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0441\u043a\u0430\u043d\u0435\u0440\u0430\u0445 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043e\u0431\u0440\u0430\u0437\u043e\u0432 Docker-\u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043e\u0432 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u044f.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-skanerah-bezopasnosti-obrazov-docker-kontejnerov\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-09-03T17:42:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-09-03T17:42:00+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilidades en esc\u00e1neres de seguridad de im\u00e1genes de contenedores Docker | ProHoster","description":"Se han publicado los resultados de las pruebas de herramientas de detecci\u00f3n.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-skanerah-bezopasnosti-obrazov-docker-kontejnerov","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0441\u043a\u0430\u043d\u0435\u0440\u0430\u0445 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043e\u0431\u0440\u0430\u0437\u043e\u0432 Docker-\u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043e\u0432 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u044b \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u043e\u0432 \u0434\u043b\u044f \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u044f.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimosti-v-skanerah-bezopasnosti-obrazov-docker-kontejnerov","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-09-03T17:42:00+00:00","article:modified_time":"2020-09-03T17:42:00+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"93156","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 11:54:00","updated":"2022-10-01 01:38:05","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/93156","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=93156"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/93156\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media\/93157"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=93156"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=93156"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=93156"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}