漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a scenario in which only the last two characters of a hexoid string need to be guessed, but this is not often relevant.) NOTE: this does not imply that, in a typical use case, attackers will be able to exploit any hexoid behavior to upload and execute their own content.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
使用具有密码学弱点缺陷的PRNG
Vulnerability Title
formidable 安全特征问题漏洞
Vulnerability Description
formidable是formidable的一个用于解析表单数据的 Node.js 模块,尤其是文件上传。 formidable 2.1.0至3.5.3之前版本存在安全特征问题漏洞,该漏洞源于hexoid生成的文件名不够安全,可能导致上传和执行恶意内容。
CVSS Information
N/A
Vulnerability Type
N/A