Sliver from v1.5.x to v1.5.39 has an improper cryptographic implementation, which allows attackers to execute a man-in-the-middle attack via intercepted and crafted responses.
The product uses a broken or risky cryptographic algorithm or protocol.
Link | Tags |
---|---|
https://github.com/tangent65536/Slivjacker | broken link |
https://github.com/advisories/GHSA-8jxm-xp43-qh3q | third party advisory |
https://github.com/BishopFox/sliver/releases/tag/v1.5.40 | release notes |
https://www.chtsecurity.com/news/04f41dcc-1851-463c-93bc-551323ad8091 | third party advisory |