Executive brief
Elliptic is a widely-used JavaScript cryptography library providing elliptic curve operations for secure communications. The library's ECDH (key exchange) implementation fails to validate that a peer's public key lies on the intended cryptographic curve, allowing an attacker to perform twist attacks that gradually leak the victim's private key through repeated key exchange operations.
Technical details
The vulnerability is a cryptographic validation weakness (CWE-327) in the secp256k1 curve implementation within elliptic/ec/key.js. The derive() function does not verify that an incoming public key point actually exists on the secp256k1 curve before using it in ECDH operations. An unauthenticated attacker with network access to a service using the library can supply specially-crafted public keys from the curve's twist to extract bits of the private key across multiple key exchanges. A patch was released in version 6.5.4.
Affected products
- Elliptic elliptic before 6.5.4
Timeline
- 2021-03-08: disclosed: GHSA advisory published
- 2021-02-02: advisory: CVE-2020-28498 published on NVD
- 2020-2021: patched: Fixed in version 6.5.4