Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Striae has a hash validation utility vulnerability
Vulnerability Description
Striae is a firearms examiner's comparison companion. A high-severity integrity bypass vulnerability existed in Striae's digital confirmation workflow prior to v3.0.0. Hash-only validation trusted manifest hash fields that could be modified together with package content, allowing tampered confirmation packages to pass integrity checks. This vulnerability is fixed in 3.0.0.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Vulnerability Type
完整性检查值验证不恰当
Vulnerability Title
Striae 安全漏洞
Vulnerability Description
Striae是Striae开源的一个枪械痕迹比对分析工具。 Striae v3.0.0之前版本存在安全漏洞,该漏洞源于数字确认工作流中仅哈希验证信任可与包内容一起修改的清单哈希字段,可能导致篡改的确认包通过完整性检查。
CVSS Information
N/A
Vulnerability Type
N/A