Vitess security audithttps://github.com/vitessio/vitess/blob/a502fceda310886223342020136db5718ace34a5/g o/vt/vtgate/evalengine/fn_crypto.go#L67 func (call *builtinSHA1) eval(env *ExpressionEnv) (eval, error) { arg, err := call.arg1(env) https://github.com/vitessio/vitess/blob/a502fceda310886223342020136db5718ace34a5/g o/vt/vtgate/evalengine/fn_crypto.go#L39 func (call *builtinMD5) eval(env *ExpressionEnv) (eval, error) { arg, err := call.arg1(env)0 码力 | 41 页 | 1.10 MB | 1 年前3
Pentest-Report Vitess 02.2019to switch to a timing-safe variant of comparing strings. Using Go’s ConstantTimeCompare in the crypto/subtle’s module is advised. Cure53, Berlin · 03/08/19 7/90 码力 | 9 页 | 155.02 KB | 1 年前3
共 2 条
- 1













