PT-2026-90829 · Dromara+1 · Orion-Visor
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
dromara orion-visor versions prior to 2.5.8
Description
A remote attack is possible due to the use of a hard-coded cryptographic key within the
encryptKey() function of the HostKeyServiceImpl class. This issue allows for the potential compromise of encrypted data handled by the system.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the
encryptKey() function to minimize the risk of exploitation.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Orion-Visor