PT-2026-46252 · Milvus Io · Milvus
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
milvus-io milvus versions prior to 2.6.14
Description
An issue exists in the Grantee ID Hash Handler component within the file internal/metastore/kv/rootcoord/kv catalog.go. This flaw allows for the use of a weak hash, which can be manipulated. Exploitation requires local access and is characterized by high complexity and difficult exploitability.
Recommendations
Apply patch 3d932f1c3e065351c4440c27abe1e6479752544d to resolve the issue.
Exploit
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Milvus