漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Improper Verification of Cryptographic Signature in Elastic Package Registry Leading to Package Integrity Bypass
Vulnerability Description
Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffic, or to otherwise influence the contents served to a self-hosted registry, to substitute a tampered package without the integrity check failing closed.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
密码学签名的验证不恰当
Vulnerability Title
Elastic Package Registry 数据伪造问题漏洞
Vulnerability Description
Elastic Package Registry是Elastic公司的一个集成组件与数据集分发服务。 Elastic Package Registry存在数据伪造问题漏洞,该漏洞源于加密签名验证不当,可能导致攻击者拦截网络流量或影响自托管注册表提供的内容,替换篡改的包而不触发完整性检查失败。
CVSS Information
N/A
Vulnerability Type
N/A