Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in DP3T-Backend-SDK before 1.1.1 for Decentralised Privacy-Preserving Proximity Tracing (DP3T). When it is configured to check JWT before uploading/publishing keys, it is possible to skip the signature check by providing a JWT token with alg=none.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
DP3T-Backend-SDK 数据伪造问题漏洞
Vulnerability Description
DP3T-Backend-SDK是一款DP3T(分散式隐私保护邻近跟踪)的后端实现。 DP3T-Backend-SDK 1.1.1之前版本中存在安全漏洞。攻击者可利用该漏洞绕过签名检查。
CVSS Information
N/A
Vulnerability Type
N/A