Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret strings when running under Lua 5.2 or later. This can potentially be used in a timing attack to reveal the contents of secret strings to an attacker.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Prosodical Thoughts Prosody 竞争条件问题漏洞
Vulnerability Description
Prosodical Thoughts Prosody是Prosodical Thoughts开源的一个应用系统。一个现代XMPP通信服务器。 Prosody 0.11.9版本之前存在安全漏洞。远程攻击者可以利用该漏洞获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A