Kraken 代理在将内容通过内容寻址缓存提交之前,未能根据请求的 SHA-256 摘要对点对点(P2P)下载的块(blobs)进行验证,而仅依赖 CRC32 校验和来验证各个数据块。位于代理间路径上的攻击者或恶意对等节点可以提供带有伪造 CRC32 校验值的内容替换,从而通过逐块检查,将攻击者选择的容器镜像层或清单文件污染缓存,并导致这些文件被其他主机重新播种(re-seeded)和执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet