GitAhead 2.5.0 至 2.7.1 版本存在一个不安全的更新机制,该机制在下载更新后不进行完整性验证或数字签名验证,并在用户第一次忽略 SSL 证书错误对话框后,永久性地忽略后续所有的 TLS 错误。网络攻击者只需一次性呈现无效的 SSL 证书,即可拦截后续自动更新检查过程,推送伪造的软件更新版本,并在用户安装时以当前用户权限执行恶意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet