漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Kronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration changes
Vulnerability Description
A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe sensitive memory segments after executing changes to its cryptographic configuration. This omission leaves raw encryption keys resident in memory after the associated structures are freed. A local attacker capable of leveraging memory disclosure techniques could exploit this flaw to retrieve the active encryption key, allowing them to decrypt cluster network communications or inject malicious packets to cause severe high-availability cluster instability.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L
Vulnerability Type
敏感数据的不恰当跨边界移除
Vulnerability Title
Kronosnet 信息泄露漏洞
Vulnerability Description
Kronosnet Kronosnet是Kronosnet组织的一个网络抽象层,专为高可用性用例而设计,其中冗余、安全性、容错性和快速故障转移是核心要求。 Kronosnet存在信息泄露漏洞,该漏洞源于密码配置管理未正确清理敏感内存段,导致加密密钥残留,本地攻击者可利用内存泄露技术获取密钥,解密集群通信或注入恶意分组造成高可用集群不稳定。
CVSS Information
N/A
Vulnerability Type
N/A