Password Shucking Vulnerability
Moderate severity
GitHub Reviewed
Published
Mar 11, 2023
in
codeigniter4/shield
•
Updated Mar 23, 2023
Package
Affected versions
< 1.0.0-beta.4
Patched versions
1.0.0-beta.4
Description
Published by the National Vulnerability Database
Mar 13, 2023
Published to the GitHub Advisory Database
Mar 13, 2023
Reviewed
Mar 13, 2023
Last updated
Mar 23, 2023
Impact
An improper implementation was found in the password storage process.
All hashed passwords stored in Shield v1.0.0-beta.3 or earlier are easier to crack than expected due to the vulnerability. Therefore, they should be removed as soon as possible.
If an attacker gets (1) the user's hashed password by Shield, and (2) the hashed password (SHA-384 hash without salt) from somewhere, the attacker may easily crack the user's password.
Patches
Upgrade to Shield v1.0.0-beta.4 or later.
After upgrading, all users’ hashed passwords should be updated (saved to the database).
See https://github.com/codeigniter4/shield/blob/develop/UPGRADING.md for details.
Workarounds
None.
References
For more information
If you have any questions or comments about this advisory:
References