Executive brief
parsel is a JavaScript package for cryptographic key derivation. The package uses an insecure one-round SHA256 hashing function instead of proper key stretching, allowing attackers to exploit keys with insufficient entropy. The package is deprecated and will not receive security updates.
Technical details
parsel implements an insecure key derivation function (KDF) by passing arbitrary-length keys through a single round of SHA256 hashing for key stretching, violating best practices for key derivation. The vulnerability (CWE-331: Insufficient Entropy) allows the use of low-entropy keys without proper computational cost to resist brute-force attacks. This affects all versions of the package. The parsel package is deprecated with no planned updates, making remediation only possible through migration to alternative cryptographic libraries that implement proper KDFs (e.g., PBKDF2, bcrypt, or scrypt).
Affected products
- parsel parsel all versions
Timeline
- 2020-09-04: disclosed