Junglewise Threat Intelligence

CVE-2021-32685: tEnvoy improper cryptographic signature verification

CVE-2021-32685 · Severity: low · CVSS 3.1 · Published 2021-06-28

Vendors: npm.

Executive brief

tEnvoy is a JavaScript library for cryptographic signing and verification. A bug in the signature verification method causes it to incorrectly accept invalid signatures as valid, bypassing authentication and integrity checks that depend on proper signature validation. This allows attackers to forge signatures and impersonate legitimate signers.

Technical details

The verifyWithMessage method in the tEnvoyNaClSigningKey class fails to properly check the .verified property returned by the underlying verify() function. Instead of checking `this.verify(signed, password).verified`, the code simply checks `this.verify(signed, password)`, which always evaluates to truthy regardless of whether the signature is actually valid. This is a logic error (CWE-347: Improper Verification of Cryptographic Signature) affecting all versions before 7.0.3. An attacker can forge any signature and have it accepted as valid, requiring only network access to the affected application. The vulnerability was patched in version 7.0.3; users should upgrade immediately and re-verify any signatures previously checked with the vulnerable method.

Affected products

  • TogaTech tEnvoy < 7.0.3

Timeline

  • 2021-06-15: disclosed
  • 2021-06-16: patched: v7.0.3 released

References

Related threats