Critical Key Derivation Flaws in pbkdf2 Affect Millions of JavaScript Projects, PoC Available (securityonline.info)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 24 Jun 12:19
https://sh.itjust.works/post/40865845

#cybersecurity

threaded - newest

koper@feddit.nl on 24 Jun 12:50 next collapse

Paywalled.

kid@sh.itjust.works on 24 Jun 13:50 next collapse

Sorry. It was not paywalled for me when I first saw. More info from different source: feedly.com/cve/CVE-2025-6545

kid@sh.itjust.works on 24 Jun 13:52 collapse
redsand@lemmy.dbzer0.com on 24 Jun 16:14 collapse

Summary copy pasta

A critical vulnerability in the pbkdf2 library affecting versions 3.0.10 through 3.1.2. The vulnerability involves improper input validation that can cause browserifying code to silently generate zero-filled cryptographic keys instead of proper ones, particularly when used in environments different from Node.js or test settings.

So pretty bad. 8.1 out of ten for setting your crypto keys to match the US nuclear arsenal in the 80s