VDB
Sign up
MEDIUM5.0

GHSA-v427-c49j-8w6x

Cleartext Storage of Sensitive Information in HMAC SHA256 Authentication

Quick fix

GHSA-v427-c49j-8w6x — codeigniter4/shield: upgrade to the fixed version with the command below.

composer require codeigniter4/shield:^1.0.0-beta.8

Details

### Impact **secretKey**, an important key for HMAC SHA256 authentication, was stored in the database in raw form.

If a malicious person somehow had access to the data in the database, they could use the key and secretKey for HMAC SHA256 authentication to send requests impersonating that person.

### Patches Upgrade to Shield v1.0.0-beta.8 or later.

After upgrading, all existing secret keys must be encrypted. See https://github.com/codeigniter4/shield/blob/develop/UPGRADING.md for details.

### Workarounds None.

### References - https://codeigniter4.github.io/shield/references/authentication/hmac/

### For more information If you have any questions or comments about this advisory: * Open an issue or discussion in [codeigniter4/shield](https://github.com/codeigniter4/shield) * Email us at [security@codeigniter.com](mailto:security@codeigniter.com)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/codeigniter4/shield
Introduced in: 0Fixed in: 1.0.0-beta.8
Fixcomposer require codeigniter4/shield:^1.0.0-beta.8

References