Vulnerability Report: GO-2023-2163

Curve KeyPairs always use the same (all-zeros) key to encrypt data, and provide no security.

For detailed information about this vulnerability, visit https://github.com/nats-io/nkeys/security/advisories/GHSA-mr45-rx8q-wcm9.

Affected Packages

  • Path
    Go Versions
    Symbols
  • from v0.4.0 before v0.4.6
    4 unexported affected symbols
    • ckp.Open
    • ckp.Seal
    • ckp.SealWithRand
    • decodePubCurveKey

Aliases

References

Credits

  • Quentin Matillat (GitHub @tinou98)

Feedback

See anything missing or incorrect? Suggest an edit to this report.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL