CVE-2023-46233 describes a critical weakness in crypto-js, a JavaScript cryptography library, specifically impacting its PBKDF2 implementation prior to version 4.2.0. The vulnerability stems from its default use of SHA1 and a single iteration, rendering it significantly weaker than industry standards and susceptible to brute-force attacks. This flaw carries a CVSS score of 9.1 (CRITICAL) due to its network-exploitable nature, low attack complexity, and high potential for compromise of confidentiality and integrity, particularly when used for password protection or signature generation. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.2.0CPE matchmatch criteria | cpe:2.3:a:crypto-js_project:crypto-js:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.