Skip to content

Insecure use of (Insecure cipher mode: ECB) in Utils.java #89

Description

@A-Amyan

We are a German research group investigating the misuse of cryptographic APIs.
We found vulnerabilities in Utils.java, Cipher at lines {986, 1002}, which can lead to an attack (e.g., Codebook attack (plaintext pattern analysis), Block replay/cut-and-paste attack).

This is our result:

    "explanation": "Direct instantiation of a Cipher object with the transformation 'AES/ECB/PKCS5Padding' for encryption.",
    "cryptographicObjectType": "Cipher",
    "codeSnippet": "Cipher aes = Cipher.getInstance(\"AES/ECB/PKCS5Padding\");",
    "vulnerabilityType": "Insecure",
    "correction": "Avoid using ECB mode since it is insecure. Use a secure cipher mode such as CBC (with a randomized IV) or GCM instead.",

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions