HIGH
S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versions of the filesystem metadata database as up-to-date, temporarily inject zero-valued bytes into files, or temporarily hide parts of files
Published Jun 10, 2018
7.5
HIGHCVSS 3.0
EPSS 1.88%
Description
Affected products
Remediation
References (4)
Change history (0)
No recorded changes yet.