Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
OpenSignLabs OpenSign - Insufficient Verification of Data Authenticity
Vulnerability Description
An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to forge document audit-trail entries via the triggerevent Parse cloud function. The function accepts viewer identity and IP address as caller-supplied parameters without authentication, allowing fabrication of arbitrary audit log entries. An attacker can tamper with the legal audit trail of any signed document, undermining non-repudiation.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
对数据真实性的验证不充分
Vulnerability Title
OpenSignLabs OpenSign 输入验证错误漏洞
Vulnerability Description
OpenSignLabs OpenSign是OpenSignLabs组织的一款数字文档签名解决方案。 OpenSignLabs OpenSign 2.37.0及之前版本存在输入验证错误漏洞,该漏洞源于triggerevent Parse云函数在未进行身份验证的情况下接受调用者提供的查看者身份和IP地址参数,允许伪造任意审计日志条目,导致攻击者可以篡改任何签名文档的法律审计跟踪,破坏不可否认性。
CVSS Information
N/A
Vulnerability Type
N/A