Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
malcontent's nested archive extraction failure can drop content from scan inputs
Vulnerability Description
malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes. Version 1.21.0 fixes the issue.
CVSS Information
N/A
Vulnerability Type
对异常条件检查或处理不恰当
Vulnerability Title
malcontent 安全漏洞
Vulnerability Description
malcontent是Chainguard开源的一个供应链攻击检测工具。 malcontent 1.21.0之前版本存在安全漏洞,该漏洞源于会删除提取失败的嵌套归档,可能遗留恶意内容。
CVSS Information
N/A
Vulnerability Type
N/A