漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting
Vulnerability Description
pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compression function, and if a collision occurs, it will result in the same storage path for two different libraries. Although the real names are under the package name /node_modoules/, there are no version numbers for the libraries they refer to. This issue has been patched in version 10.0.0.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
Vulnerability Type
可逆的单向哈希
Vulnerability Title
pnpm 安全漏洞
Vulnerability Description
pnpm是pnpm开源的一个包管理器。 pnpm 10.0.0之前版本存在安全漏洞,该漏洞源于路径缩短函数使用md5可能导致不同库存储路径冲突。
CVSS Information
N/A
Vulnerability Type
N/A