Unauthorized access to files In github.com/sparkle-project/sparkle
Description
Sparkle Signing Checks Bypass A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
swifturl | 2.6.4 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.