VDB
Sign up
LOW2.6

GHSA-rj29-j2g4-77q8

[TagAwareCipher] - Decryption Failure (Regex Match)

Quick fix

GHSA-rj29-j2g4-77q8 — ilicmiljan/secure-props: upgrade to the fixed version with the command below.

composer require ilicmiljan/secure-props:^1.2.2

Details

### Impact

Vulnerability in **SecureProps** involves a regex failing to detect tags during decryption of encrypted data.

This occurs when the encrypted data has been encoded with `NullEncoder` and passed to `TagAwareCipher`, and contains special characters such as `\n`. As a result, the decryption process is skipped since the tags are not detected. This causes the encrypted data to be returned in plain format.

The vulnerability affects users who implement `TagAwareCipher` with any base cipher that has `NullEncoder` (not default).

### Patches

The patch for the issue has been released. Users are advised to update to version **1.2.2**.

### Workarounds

**The main recommendation is to update to the latest version as there are no breaking changes.**

If that's not possible, you can use the default `Base64Encoder` with the base cipher decorated with `TagAwareCipher` to prevent special characters in the encrypted string from interfering with regex tag detection logic.

This workaround is safe but may involve double encoding since `TagAwareCipher` uses `Base64Encoder` by default. ### References

Reported issue: https://github.com/IlicMiljan/Secure-Props/issues/20 Pull request resolving bug: https://github.com/IlicMiljan/Secure-Props/pull/21

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/ilicmiljan/secure-props
Introduced in: 1.2.0Fixed in: 1.2.2
Fixcomposer require ilicmiljan/secure-props:^1.2.2

References