Executive brief
EnroCrypt is a Python library that provides cryptographic hashing functionality. The library used MD5, an insecure hashing algorithm known to be vulnerable to collision and preimage attacks, for password hashing operations. This allows attackers to feasibly crack password hashes and recover the original passwords, compromising any authentication or data protection relying on these hashes.
Technical details
The vulnerability is an instance of improper cryptographic algorithm selection (CWE-327, CWE-328, CWE-916) in the hashing.py module, where MD5 is used for password hashing. MD5 is cryptographically broken and should not be used for security-sensitive applications; it is susceptible to collision attacks, preimage attacks, and password cracking due to insufficient computational effort and weak entropy properties. The vulnerability affects all versions prior to 1.1.4 and is exploitable without authentication or special preconditions—any code using the enrocrypt library's MD5-based hashing functions is vulnerable. An attacker can recover plaintext passwords from MD5 hashes through dictionary attacks or online lookup tables. The vulnerability was patched in version 1.1.4, which replaced MD5 with a more secure hashing algorithm.
Affected products
- EnroCrypt enrocrypt <1.1.4
Timeline
- 2021-11-06: disclosed
- 2021-11-10: advisory
- 2021-11-08: patched: Fixed in version 1.1.4