Description
s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentication if message decryption is used as an authentication mechanism via a crafted symmetrically encrypted PGP message.
Recommendation
Update the openpgp package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.3.0
- Patched version(s): 1.3.0
References
Related Issues
- Malicious Matrix homeserver can leak truncated message content of messages it shouldn't have access to - CVE-2024-39691
- Clipboard feature vulnerability allowing to inject arbitrary HTML into the editor using paste functionality - CVE-2021-32809
- Regular Expression Denial of Service in ansi2html - CVE-2015-9239
- @tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files - CVE-2026-33949
You might also like:
- Tags:
- npm
- openpgp
Anything's wrong? Let us know Last updated on January 27, 2023


