Docker Notary是美国Docker公司的一套用于发布和管理可信内容集合的工具。 Docker Notary 0.1之前版本中的gotuf/signed/verify.go文件存在安全漏洞。攻击者可通过将RSA-PSS密钥强制解析成Ed25519 elliptic-curve数据利用该漏洞伪造签名。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-8893 | Z-BlogPHP 跨站请求伪造漏洞 | |
| CVE-2018-8908 | Frog CMS 跨站请求伪造漏洞 | |
| CVE-2018-9161 | Prisma Industriale Checkweigher PrismaWEB 安全漏洞 | |
| CVE-2018-9162 | Contec Smart Home 安全漏洞 | |
| CVE-2015-9259 | Docker Notary 安全漏洞 | |
| CVE-2018-9159 | Spark 安全漏洞 | |
| CVE-2018-9160 | SickRage 安全漏洞 | |
| CVE-2017-18255 | Linux kernel 安全漏洞 |
No comments yet