This application relates to a
vulnerability detection method, apparatus, device, medium, and product, and pertains to the field of
cloud computing technology. The method includes: splitting an encrypted version string to obtain encrypted
ciphertext, sending
timestamp information, and
obfuscation feature string; verifying the encrypted
ciphertext, sending
timestamp information, and
obfuscation feature string to obtain a
verification result, and retrieving the decryption key if the result passes; decrypting the encrypted
ciphertext with the decryption key to obtain target format version information; retrieving the
software name, major version number, minor version number, and patch version number from the target format version information, and matching the
software name against a pre-stored rule base
list of target
vulnerability data; obtaining a
vulnerability risk assessment result and a remediation result based on the major version number, minor version number, patch version number, vulnerability
impact scope, and the target version for remediation; and generating a
vulnerability detection report based on the vulnerability
risk assessment result and the remediation result. Decrypting the encrypted version string and matching the vulnerability scope effectively improves the timeliness of
vulnerability detection.