Junglewise Threat Intelligence

CVE-2023-46133: crypto-es PBKDF2 insufficient iteration count and weak hash algorithm

CVE-2023-46133 · Severity: low · CVSS 3.1 · Published 2023-10-25

Vendors: npm.

Executive brief

crypto-es is a JavaScript cryptography library used to derive encryption keys and protect passwords. The PBKDF2 key derivation function defaults to only 1 iteration and SHA-1 hashing, making it approximately 1,000 times weaker than standards from 1993 and 1.3 million times weaker than current industry recommendations. Attackers can forge cryptographic signatures, decrypt password-protected data, and compromise account security with minimal computational cost (approximately $45,000 for proof-of-concept attacks).

Technical details

The vulnerability is a weak cryptographic configuration in the PBKDF2 key derivation function (CWE-916, CWE-328). crypto-es defaults to SHA-1 (cryptographically broken since 2005) and a single iteration, versus the 1993 recommendation of 1,000 iterations and modern OWASP guidance of 1,300,000 iterations. The root cause is the lack of secure defaults in the PBKDF2 implementation; unlike the WebCrypto standard, it does not require or validate iteration count. Network attackers with knowledge of only the plaintext prefix can exploit SHA-1 length extension attacks to forge signatures and bypass salt/pepper protections. Applications using PBKDF2 for password storage or key derivation without explicit parameter overrides are vulnerable; the advisory notes 432+ public GitHub repositories use this functionality with default weak parameters. A patch was released in version 2.1.0.

Affected products

  • entronad crypto-es All versions before 2.1.0

Timeline

  • 2023-10-25: disclosed
  • 2023-10-25: patched: Fixed in version 2.1.0

References