漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
yoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupByContentHash weak hash
Vulnerability Description
A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash. The attack needs to be launched locally. The attack requires a high level of complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
可逆的单向哈希
Vulnerability Title
grepai 加密问题漏洞
Vulnerability Description
grepai是Yoan Bernabeu个人开发者的一款基于语义搜索的代码理解工具。 grepai 0.35.0版本存在加密问题漏洞,该漏洞源于Postgres嵌入缓存组件中文件indexer/chunker.go的PostgresStore.LookupByContentHash函数对参数content_hash操作不当,可能导致使用弱哈希。攻击者需本地利用,且攻击复杂度高。
CVSS Information
N/A
Vulnerability Type
N/A