Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
RELATE: Timing Attack Vulnerability in course/auth.py — check_sign_in_key()
Vulnerability Description
RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via commit 2f68e16.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
通过时间差异性导致的信息暴露
Vulnerability Title
RELATE 安全漏洞
Vulnerability Description
RELATE是Andreas Klöckner个人开发者的一个基于网络的课件包。 RELATE存在安全漏洞,该漏洞源于course/auth.py中的check_sign_in_key()函数容易受到时序攻击。
CVSS Information
N/A
Vulnerability Type
N/A