在 andreashappe 的 cochise 软件(版本 0.4.1 及更早版本)中发现了一个安全弱点。受影响的是组件“SSH 主机密钥处理器”中,位于文件 的 函数。通过特定的操作可能导致证书验证不当。该漏洞可被远程利用,但攻击复杂度较高,且利用难度较大。该漏洞的细节已公开,可被用于攻击。项目方较早地通过问题报告获知了该问题,但截至目前尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| andreashappe | cochise | 0.4.0 |
cpe:2.3:a:andreashappe:cochise:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet