Home

Description

LangChain4j-AIDeepin is a Retrieval enhancement generation (RAG) project. Prior to 3.5.0, LangChain4j-AIDeepin uses MD5 to hash files, which may cause file upload conflicts. This issue is fixed in 3.5.0.

PUBLISHED Reserved 2024-12-29 | Published 2025-01-06 | Updated 2025-01-06 | Assigner GitHub_M




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Problem types

CWE-328: Use of Weak Hash

Product status

< 3.5.0
affected

References

github.com/...deepin/security/advisories/GHSA-cv5r-73vf-8x7v

github.com/...ommit/3cf625c5044a151a8cbcbdf98e10b4b46b8a975a

cve.org (CVE-2025-21604)

nvd.nist.gov (CVE-2025-21604)

Download JSON