脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
xkeys Seal encryption used fixed key for all encryption
脆弱性説明
NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication. This is used in nats-server 2.10 (Sep 2023) and newer for authentication callouts. In nkeys versions 0.4.0 through 0.4.5, corresponding with NATS server versions 2.10.0 through 2.10.3, the nkeys library's `xkeys` encryption handling logic mistakenly passed an array by value into an internal function, where the function mutated that buffer to populate the encryption key to use. As a result, all encryption was actually to an all-zeros key. This affects encryption only, not signing. FIXME: FILL IN IMPACT ON NATS-SERVER AUTH CALLOUT SECURITY. nkeys Go library 0.4.6, corresponding with NATS Server 2.10.4, has a patch for this issue. No known workarounds are available. For any application handling auth callouts in Go, if using the nkeys library, update the dependency, recompile and deploy that in lockstep.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
脆弱性タイプ
使用硬编码的密码学密钥
脆弱性タイトル
NATS Server 安全漏洞
脆弱性説明
NATS Server是一款开源消息系统。该系统主要用于云原生应用、物联网消息传递和微服务架构等。 NATS Server 2.10.0 到2.10.3版本、nkeys 0.4.0 到 0.4.5版本存在安全漏洞,该漏洞源于nkeys 库的xkeys加密处理逻辑错误地将数组按值传递到内部函数中,改变了缓冲区要使用的加密密钥,导致所有加密实际上都是全零密钥。
CVSS情報
N/A
脆弱性タイプ
N/A