Weaviate v1.39.3 修复高危凭证泄露漏洞
Weaviate 修复了 Google 模块的高危漏洞,如果你用了这些模块得赶紧升级。
Weaviate v1.39.3 修复了影响 Google 支持模块的高危凭证泄露漏洞。该漏洞影响 text2vec-google、multi2vec-google 和 generative-google 模块,未经验证的 apiEndpoint 设置可能导致 Google 凭证被发送到非预期主机。受影响版本(< v1.39.3)用户应升级至 v1.39.3 或更高版本。Weaviate Cloud 和 Marketplace 客户已修复此漏洞,目前无证据表明该漏洞已被利用。
Weaviate `v1.39.3` includes a fix for a high-severity credential disclosure vulnerability affecting Weaviate's Google-backed modules. The vulnerability affects `text2vec-google`, `multi2vec-google`, and `generative-google`, where an unvalidated `apiEndpoint` setting could cause Google credentials to be sent to an unintended host. Users running impacted versions of Weaviate (`< v1.39.3`) should upgrade to `v1.39.3` or later. Weaviate Cloud and Marketplace customers have already been patched and we have no indication that the vulnerability has been exploited. Thank you to Syed Anas Mohiuddin for responsibly reporting the issue through our Vulnerability Disclosure Program. Full details: weaviate.io/blog/weaviate-… 💬 0 🔄 1 ❤️ 2 👀 155 📊 1 ⚡