Use of Hard-coded Cryptographic Key
CVE-2024-41260
Summary
A static initialization vector (IV) in the "encrypt" function of netbird from v0.23.2 through v0.29.1, allows attackers to obtain sensitive information.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- HIGH
- NONE
CWE-321 - Use of Hard-coded Cryptographic Key
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
References
Advisory Timeline
- Published