Am I affected?

type your cloak_ecto version to check

Description

Use of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloak_ecto and danielberkompas cloak allows an attacker who holds the hashed values and the configured secret to brute-force low-entropy plaintexts much faster than configured.

The dump/1 callback that Cloak.Ecto.PBKDF2 (Cloak.Fields.PBKDF2 in cloak before the Ecto code moved to cloak_ecto) injects into a field module calls :pbkdf2.pbkdf2/4 with config[:size] in the iteration-count position. The :iterations setting is validated but never used. With the cloak_ecto defaults (iterations: 600_000, size: 32) each hash runs 32 PBKDF2 rounds instead of 600,000, so offline guessing of values such as email addresses costs about 18,750 times less than configured.

This issue affects cloak_ecto: from 1.0.0-alpha.0 onward; cloak: from 0.7.0 before 1.0.0-alpha.0.

Proof of concept

  1. Define a field module with use Cloak.Ecto.PBKDF2 and configure only a :secret, so that the defaults iterations: 600_000 and size: 32 apply.
  2. Call dump/1 on a value.
  3. Compare the result with :pbkdf2.pbkdf2({:hmac, :sha256}, value, secret, 32) and with the same call at 600,000 rounds. It matches the 32-round hash, not the 600,000-round hash, and returns in microseconds instead of about one second.

Weaknesses & attack patterns

Weakness

CWE-916 · Use of Password Hash With Insufficient Computational Effort in catalog → MITRE ↗

Attack patterns

CAPEC-55 · Rainbow Table Password Cracking MITRE ↗

An attacker who obtains a database dump and the PBKDF2 secret can recover hashed values with low entropy, such as email addresses, by offline guessing at a cost far below what the configuration promises.

Affected — Hex / cloak_ecto Hex.pm ↗ Repository ↗

≥ 1.0.0-alpha.0 and up affected
every other version: unaffected
cpe cpe:2.3:a:danielberkompas:cloak_ecto:*:*:*:*:*:*:*:*
version type semver
modules · source files
modules 'Elixir.Cloak.Ecto.PBKDF2'
source files lib/cloak_ecto/types/pbkdf2.ex

Affected — GitHub / danielberkompas/cloak_ecto Repository ↗

≥ a8fa164 and up affected
every other version: unaffected
cpe cpe:2.3:a:danielberkompas:cloak_ecto:*:*:*:*:*:*:*:*
version type git
modules · source files
modules 'Elixir.Cloak.Ecto.PBKDF2'
source files lib/cloak_ecto/types/pbkdf2.ex

Affected — Hex / cloak Hex.pm ↗ Repository ↗

≥ 0.7.0 < 1.0.0-alpha.0 affected
every other version: unaffected
cpe cpe:2.3:a:danielberkompas:cloak:*:*:*:*:*:*:*:*
version type semver
modules · source files
modules 'Elixir.Cloak.Fields.PBKDF2'
source files lib/cloak/fields/pbkdf2.ex

Affected — GitHub / danielberkompas/cloak Repository ↗

≥ 8699e64 < 681c970 affected
every other version: unaffected
cpe cpe:2.3:a:danielberkompas:cloak:*:*:*:*:*:*:*:*
version type git
modules · source files
modules 'Elixir.Cloak.Fields.PBKDF2'
source files lib/cloak/fields/pbkdf2.ex

Workarounds

Override dump/1 in the field module that uses Cloak.Ecto.PBKDF2, so that it calls :pbkdf2.pbkdf2/5 with the configured :iterations and :size. Then recompute all stored hashes, because the existing values no longer match.

References

Credits

Peter Ullrich Finder Reporter
Jonatan Männchen / EEF Coordinator

CVSS breakdown

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
« All CVEs