CVE-2021-32685
Summary
| CVE | CVE-2021-32685 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-16 01:15:00 UTC |
| Updated | 2021-06-23 20:09:00 UTC |
| Description | tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any signature that has a SHA-512 hash matching the SHA-512 hash of the message even if the signature was invalid. This issue is patched in version 7.0.3. As a workaround: In `tenvoy.js` under the `verifyWithMessage` method definition within the `tEnvoyNaClSigningKey` class, ensure that the return statement call to `this.verify` ends in `.verified`. |
Risk And Classification
Problem Types: CWE-347
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release Critical Security Fix in verifyWithMessage · TogaTech/tEnvoy · GitHub | MISC | github.com | |
| Critical security fix in verifyWithMessage · TogaTech/tEnvoy@a121b34 · GitHub | MISC | github.com | |
| Improper Verification of Cryptographic Signature in tenvoy · Advisory · TogaTech/tEnvoy · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982088 Nodejs (npm) Security Update for tenvoy (GHSA-5w25-hxp5-h8c9)