Executive brief
The keypair library, used for generating RSA encryption keys in JavaScript environments, contains a flaw that results in the creation of weak, predictable security keys. Because the random number generator used to build these keys is flawed, an attacker could potentially guess a victim's private key, allowing them to decrypt private communications or gain unauthorized access to accounts. This issue is particularly severe for applications running in Node.js environments where the library fails to use secure system-level random number sources.
Technical details
The keypair library (versions <= 1.0.3) suffers from multiple PRNG weaknesses, primarily affecting Node.js environments. First, a variable shadowing bug causes the library to fail to detect the native Node.js 'crypto' module, falling back to an insecure Lehmer LCG seeded by Math.random(). Second, a coding error in the fallback path uses a double 'String.fromCharCode' conversion (String.fromCharCode(String.fromCharCode(next & 0xFF))), which results in approximately 97% of the entropy seed bytes being set to zero. This drastically reduces the keyspace, leading to the generation of identical or easily guessable RSA keys. Attackers can exploit this to perform key recovery attacks, decrypting traffic or impersonating users. The issue is fixed in version 1.0.4 by correctly requiring the crypto module and fixing the encoding logic.
Affected products
- juliangruber keypair <= 1.0.3
Timeline
- 2021-09-30: disclosed: Reported to maintainer by GitHub Security Lab
- 2021-10-11: patched: Version 1.0.4 released
- 2021-10-11: advisory