Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backups. This is arguably a Principle of Least Surprise violation because "the user likely wanted to encrypt all file activity."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WAL-G 代码问题漏洞
Vulnerability Description
WAL-G是PostgreSQL、MySQL/MariaDB 和 MS SQL Server(MongoDB 和 Redis 测试版)的档案恢复工具。 WAL-G 1.1之前存在代码问题漏洞,该漏洞源于在非 libsodium 构建中缺少对 libsodium 键是否存在的检查。
CVSS Information
N/A
Vulnerability Type
N/A