Executive brief
crypto-js is a JavaScript library for cryptographic operations used by thousands of applications to derive encryption keys from passwords. The PBKDF2 key-derivation function in crypto-js defaults to only 1 iteration and SHA1 hashing, making it 1,000 times weaker than 1993 standards and 1.3 million times weaker than current industry recommendations. Attackers can forge cryptographic signatures or compromise password-protected data with relatively modest computational resources.
Technical details
The vulnerability exists in the crypto-js PBKDF2 implementation, which defaults to a single iteration count and SHA1 as the hash algorithm, rather than the OWASP-recommended 1,300,000 iterations with SHA256. PBKDF2 is a key-derivation function used to stretch password entropy and protect password storage; its security relies critically on a high iteration count to slow down brute-force attacks. The weak defaults make offline password cracking and signature forgery attacks computationally feasible: an attacker can generate colliding signatures for known inputs for approximately $45,000 in compute costs, and due to length-extension weaknesses, can forge signatures for unknown data prefixed by known values even when salts or peppers are applied. The vulnerability affects all versions of crypto-js since its creation; the package is unmaintained and no official patch is available, though version 4.2.0 or later may contain fixes via community contributions.
Affected products
- crypto-js crypto-js all versions before 4.2.0
Timeline
- 2023-10-25: disclosed
- 2023-10-25: advisory