在 topoteretes cognee 1.5.4 及之前版本中发现了一个安全漏洞。受影响的组件是 JWT 签名密钥处理器(JWT Signing Key Handler)中的函数 ,该函数位于文件 中。对参数 的操作会导致出现硬编码凭据的问题。此漏洞可被远程利用。升级至 1.6.0 版本即可修复该问题。该补丁的提交标识为 fa65fc0cd86cdba48d19aa76e36be862be982f5d。建议尽快升级受影响的组件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| topoteretes | cognee | 1.5.0 |
cpe:2.3:a:topoteretes:cognee:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet