Menu

#1637 Signature signatures on executables and installer use vulnerable SHA1 hash

None
open-accepted
nobody
None
5
2025-08-19
2024-10-10
No

SHA1 has been known to be vulnerable for a long time, as reported by Google:
https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html
Digital signatures should be using SHA256 or SHA512, not SHA1, or they offer false protection.

Discussion

  • Zefram Cochrane

    Zefram Cochrane - 2024-10-10

    No way to edit ticket title. Sigh.

     
  • Anton

    Anton - 2024-10-10
    • status: open --> open-accepted
    • Group: -->
     
  • Anton

    Anton - 2025-08-19

    will be changed to sha256 in the next release

     

Log in to post a comment.

MongoDB Logo MongoDB