Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vrmr-f2qh-3hhf

Опубликовано: 02 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Improper use of cryptographic key in wal-g

WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backups. This is arguably a Principle of Least Surprise violation because "the user likely wanted to encrypt all file activity."

Пакеты

Наименование

github.com/wal-g/wal-g

go
Затронутые версииВерсия исправления

< 1.1

1.1

EPSS

Процентиль: 39%
0.0017
Низкий

7.5 High

CVSS3

Дефекты

CWE-922

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backups. This is arguably a Principle of Least Surprise violation because "the user likely wanted to encrypt all file activity."

EPSS

Процентиль: 39%
0.0017
Низкий

7.5 High

CVSS3

Дефекты

CWE-922