Vulnerabilities/

OpenPGP 1.2.0 and earlier decrypts arbitrary messages

Severity:
High

Description

s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentication if message decryption is used as an authentication mechanism via a crafted symmetrically encrypted PGP message.

Recommendation

Update the openpgp package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
openpgp
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing