A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
2025-02-04T20:15:49.763
2025-08-05T14:35:15.903
Analyzed
CVSSv3.1: 7.3 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sparkle-project | sparkle | < 2.6.4 | Yes |
Operating System | netapp | hci_compute_node | - | Yes |
Application | netapp | oncommand_workflow_automation | - | Yes |
Operating System | netapp | hci_compute_node | - | Yes |