Filtered by vendor Wal-g Project
Subscriptions
Filtered by product Wal-g
Subscriptions
Total
1 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2021-38599 | 1 Wal-g Project | 1 Wal-g | 2024-11-21 | 7.5 High |
WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backups. This is arguably a Principle of Least Surprise violation because "the user likely wanted to encrypt all file activity." |
Page 1 of 1.