CVE-2021-32685
tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any signature that has a SHA-512 hash matching the SHA-512 hash of the message even if the signature was invalid. This issue is patched in version 7.0.3. As a workaround: In `tenvoy.js` under the `verifyWithMessage` method definition within the `tEnvoyNaClSigningKey` class, ensure that the return statement call to `this.verify` ends in `.verified`.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.66% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-347
- Affected
- togatech/tenvoy
- Source
- security-advisories@github.com
References
- https://github.com/TogaTech/tEnvoy/commit/a121b34a45e289d775c62e58841522891dee686bPatch, Third Party Advisory
- https://github.com/TogaTech/tEnvoy/releases/tag/v7.0.3Release Notes, Third Party Advisory
- https://github.com/TogaTech/tEnvoy/security/advisories/GHSA-7r96-8g3x-g36mThird Party Advisory
- https://github.com/TogaTech/tEnvoy/commit/a121b34a45e289d775c62e58841522891dee686bPatch, Third Party Advisory
- https://github.com/TogaTech/tEnvoy/releases/tag/v7.0.3Release Notes, Third Party Advisory
- https://github.com/TogaTech/tEnvoy/security/advisories/GHSA-7r96-8g3x-g36mThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.