{"id":72053,"date":"2020-03-01T08:42:47","date_gmt":"2020-03-01T05:42:47","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimost-v-apache-tomcat-pozvolyayushhaya-podstavit-jsp-kod-i-poluchit-fajly-web-prilozhenij"},"modified":"2020-03-03T16:10:21","modified_gmt":"2020-03-03T13:10:21","slug":"uyazvimost-v-apache-tomcat-pozvolyayushhaya-podstavit-jsp-kod-i-poluchit-fajly-web-prilozhenij","status":"publish","type":"post","link":"https:\/\/prohoster.info\/et\/blog\/news\/uyazvimost-v-apache-tomcat-pozvolyayushhaya-podstavit-jsp-kod-i-poluchit-fajly-web-prilozhenij","title":{"rendered":"Haavatavus Apache Tomcat'is, mis v\u00f5imaldab sisestada JSP-koodi ja ligip\u00e4\u00e4seda veebirakenduste failidele","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Hiina ettev\u00f5tte Chaitin Tech teadlased on tuvastanud <noindex><a rel=\"nofollow\" href=\"https:\/\/www.chaitin.cn\/en\/ghostcat\">haavatavus<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-1938\">CVE-2020-1938<\/a><\/noindex>) <noindex><a rel=\"nofollow\" href=\"http:\/\/tomcat.apache.org\/\">Apache Tomcat<\/a><\/noindex>, avatud Java Servlet, JavaServer Pages, Java Expression Language ja Java WebSocket'i tehnoloogiate rakendus. Haavatavusele on antud koodnimi Ghostcat ja selle kriitiline ohtlikkuse tase on 9.8 CVSS. Probleem v\u00f5imaldab vaikimisi konfiguratsioonis lugeda mis tahes faili sisu veebirakenduse kataloogist, sealhulgas seadistustele ja rakenduse l\u00e4htekoodile, edastades p\u00e4ringu v\u00f5rgupordile 8009.<\/p>\n<p>Haavatavus v\u00f5imaldab ka importida teisi faile rakenduskoodi, mis v\u00f5ib v\u00f5imaldada koodi t\u00e4itmist serveris, kui rakendus lubab faile serverisse laadida (n\u00e4iteks v\u00f5ib r\u00fcndaja laadida JSP-skripti piltide \u00fcleslaadimisvormi kaudu). R\u00fcnnak v\u00f5ib toimuda, kui on v\u00f5imalik saata p\u00e4ring v\u00f5rgupordile, millel on AJP k\u00e4itleja. Esialgsetel andmetel on internetis <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/hrbrmstr\/status\/1233766331314581509\">leidnud<\/a><\/noindex> \u00fcle 1,2 miljoni hosti, mis aktsepteerivad p\u00e4ringuid AJP protokolli kaudu. <\/p>\n<p> Haavatavus esineb AJP protokollis, mitte <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/solutions\/4851251\">on p\u00f5hjustatud<\/a><\/noindex> rakenduse teostamise veast. Lisaks HTTP (port 8080) \u00fchenduste vastuv\u00f5tmisele v\u00f5imaldab Apache Tomcat vaikimisi juurdep\u00e4\u00e4su veebirakendusele AJP protokolli kaudu (<noindex><a rel=\"nofollow\" href=\"https:\/\/tomcat.apache.org\/connectors-doc\/ajp\/ajpv13a.html\">Apache Jserv Protocol<\/a><\/noindex>, port 8009), mis on binaarne variant HTTP, optimeeritud suurema j\u00f5udluse saavutamiseks, ja seda kasutatakse tavaliselt Tomcat-serverite klastrite loomiseks v\u00f5i Tomcat'i suhtlemise kiiremaks muutmiseks tagasip\u00f6\u00f6rdelise proksi v\u00f5i koormuse tasakaalustaja kaudu.<\/p>\n<p>AJP pakub vaikimisi funktsiooni juurdep\u00e4\u00e4suks serveri failidele, mida v\u00f5ib kasutada ka mitteavalike failide saamiseks. Eeldatakse, et juurdep\u00e4\u00e4s AJP-le on avatud ainult usaldusv\u00e4\u00e4rsetele serveritele, kuid tegelikult k\u00e4ivitati vaikimisi Tomcat'i k\u00e4itleja k\u00f5igil v\u00f5rguliideseid, ning p\u00e4ringud v\u00f5eti vastu ilma autentimiseta. Juurdep\u00e4\u00e4s on v\u00f5imalik mis tahes failidele veebirakenduses, sealhulgas WEB-INF, META-INF sisu ja mis tahes muude kataloogide sisu, mida saab k\u00e4tte kutsudes ServletContext.getResourceAsStream(). AJP v\u00f5imaldab ka kasutada mis tahes faili veebirakenduse kataloogides skriptina JSP.<\/p>\n<p>Probleem ilmeneb alates 13 aastat tagasi v\u00e4lja antud Tomcat 6.x harust. Lisaks Tomcat'ile on probleem ka <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/solutions\/4851251\">puudutab<\/a><\/noindex> ja selle p\u00f5hjal t\u00f6\u00f6tavad tooted, nagu Red Hat JBoss Web Server (JWS), JBoss Enterprise Application Platform (EAP), samuti iseseisvad veebirakendused, mis kasutavad <noindex><a rel=\"nofollow\" href=\"https:\/\/spring.io\/projects\/spring-boot\">Spring Boot<\/a><\/noindex>. Sarnane haavatavus (CVE-2020-1745) <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/solutions\/4851251\">ainult hiina keeles.<\/a><\/noindex> veebiserveris <noindex><a rel=\"nofollow\" href=\"http:\/\/undertow.io\/\">Undertow<\/a><\/noindex>, mis on kasutusel Wildfly rakenduste serveris. JBossis ja Wildfly's on AJP-protokoll vaikimisi lubatud ainult standalone-full-ha.xml, standalone-ha.xml ja ha\/full-ha profiilides domain.xml-failis. Spring Bootis on AJP tugi vaikimisi keelatud. Praegu on erinevad grupid ette valmistanud rohkem kui tosin t\u00f6\u00f6tavat eksploitide n\u00e4idet (<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/dacade\/cve-2020-1938\">1<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/ze0r\/GhostCat-LFI-exp\">2<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/laolisafe\/CVE-2020-1938\">3<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/00theway\/Ghostcat-CNVD-2020-10487\">4<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/xindongzhuaizhuai\/CVE-2020-1938\">5<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/0nise\/CVE-2020-1938\">6<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/nibiwodong\/CNVD-2020-10487-Tomcat-ajp-POC\">7<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/YDHCUI\/CNVD-2020-10487-Tomcat-Ajp-lfi\">8<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/LandGrey\/ClassHound\">9<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/fairyming\/CVE-2020-1938\">10<\/a><\/noindex>,<br \/>\n    <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/jiangsir404\/POC-S\">11<\/a><\/noindex>). <\/p>\n<p>Haavatavus on k\u00f5rvaldatud Tomcat'i v\u00e4ljaannetes <noindex><a rel=\"nofollow\" href=\"https:\/\/tomcat.apache.org\/security-9.html#Fixed_in_Apache_Tomcat_9.0.31\">9.0.31<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/tomcat.apache.org\/security-8.html#Fixed_in_Apache_Tomcat_8.5.51\">8.5.51<\/a><\/noindex> ja <noindex><a rel=\"nofollow\" href=\"https:\/\/tomcat.apache.org\/security-7.html#Fixed_in_Apache_Tomcat_7.0.100\">7.0.100<\/a><\/noindex> (6.x haru hoidmine  <noindex><a rel=\"nofollow\" href=\"https:\/\/tomcat.apache.org\/security-6.html\">Samas on Fedora 32<\/a><\/noindex>). Uuenduse ilmumist distributsioonides saab j\u00e4lgida nende lehtede kaudu: <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-1938\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2020\/CVE-2020-1938.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2020-1938\">RHEL<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1806805\">Fedora<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.suse.com\/security\/cve\/CVE-2020-1938\/\">SUSE<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"http:\/\/www.vuxml.org\/freebsd\/\">FreeBSD<\/a><\/noindex>. Kaitseks Tomcat AJP Connectori teenuse sulgemiseks v\u00f5ib olla alternatiivina l\u00f5hna siduda kuulamisport localhostiga v\u00f5i kommenteerida rida Connector port = &#171;8009&#187;, kui see ei ole vajalik, v\u00f5i <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/security\/cve\/CVE-2020-1938\">seadistada<\/a><\/noindex> autentitud juurdep\u00e4\u00e4s atribuutide &#171;secret&#187; ja &#171;address&#187; kaudu, kui teenust kasutatakse teiste serverite ja mod_jk ning mod_proxy_ajp (mod_cluster ei toeta autentimist) vaheliseks suhtlemiseks. <\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Allikas: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52459\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u0438\u0442\u0430\u0439\u0441\u043a\u043e\u0439 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Chaitin Tech \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2020-1938) \u0432 Apache Tomcat, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0439 Java Servlet, JavaServer Pages, Java Expression Language \u0438 Java WebSocket. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d\u043e \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f Ghostcat \u0438 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 (9.8 CVSS). \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0437\u0430\u043f\u0440\u043e\u0441\u0430 \u043f\u043e \u0441\u0435\u0442\u0435\u0432\u043e\u043c\u0443 \u043f\u043e\u0440\u0442\u0443 8009 \u043f\u0440\u043e\u0447\u0438\u0442\u0430\u0442\u044c \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0435 \u043b\u044e\u0431\u044b\u0445 \u0444\u0430\u0439\u043b\u043e\u0432 \u0438\u0437 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-72053","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u0438\u0442\u0430\u0439\u0441\u043a\u043e\u0439 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Chaitin Tech \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/et\/blog\/news\/uyazvimost-v-apache-tomcat-pozvolyayushhaya-podstavit-jsp-kod-i-poluchit-fajly-web-prilozhenij\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"et_EE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Apache Tomcat, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u044c JSP-\u043a\u043e\u0434 \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0444\u0430\u0439\u043b\u044b web-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u0438\u0442\u0430\u0439\u0441\u043a\u043e\u0439 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Chaitin Tech \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/et\/blog\/news\/uyazvimost-v-apache-tomcat-pozvolyayushhaya-podstavit-jsp-kod-i-poluchit-fajly-web-prilozhenij\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-03-01T05:42:47+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-03T13:10:21+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Haavatavus Apache Tomcat'is, mis v\u00f5imaldab sisestada JSP-koodi ja saada veebirakenduste faile | ProHoster","description":"Hiina ettev\u00f5tte Chaitin Tech teadlased avastasid haavatavuse (","canonical_url":"https:\/\/prohoster.info\/et\/blog\/news\/uyazvimost-v-apache-tomcat-pozvolyayushhaya-podstavit-jsp-kod-i-poluchit-fajly-web-prilozhenij","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"et_EE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Apache Tomcat, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u044c JSP-\u043a\u043e\u0434 \u0438 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0444\u0430\u0439\u043b\u044b web-\u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u0438\u0442\u0430\u0439\u0441\u043a\u043e\u0439 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Chaitin Tech \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (","og:url":"https:\/\/prohoster.info\/et\/blog\/news\/uyazvimost-v-apache-tomcat-pozvolyayushhaya-podstavit-jsp-kod-i-poluchit-fajly-web-prilozhenij","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-03-01T05:42:47+00:00","article:modified_time":"2020-03-03T13:10:21+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"72053","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 18:51:22","updated":"2022-10-08 06:25:27","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/posts\/72053","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/comments?post=72053"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/posts\/72053\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/media?parent=72053"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/categories?post=72053"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/et\/wp-json\/wp\/v2\/tags?post=72053"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}