schlunker
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Kid@sh.itjust.worksM to Cybersecurity@sh.itjust.worksEnglish · 13 days ago

Critical Key Derivation Flaws in pbkdf2 Affect Millions of JavaScript Projects, PoC Available

securityonline.info

external-link
message-square
4
fedilink
5
external-link

Critical Key Derivation Flaws in pbkdf2 Affect Millions of JavaScript Projects, PoC Available

securityonline.info

Kid@sh.itjust.worksM to Cybersecurity@sh.itjust.worksEnglish · 13 days ago
message-square
4
fedilink
Two critical flaws (CVE-2025-6545, CVE-2025-6547, CVSS 9.1) in pbkdf2 npm package allow silent compromise of cryptographic keys. Update to 3.1.3+ immediately!
alert-triangle
You must log in or register to comment.
  • redsand@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    3
    ·
    13 days ago

    Summary copy pasta

    A critical vulnerability in the pbkdf2 library affecting versions 3.0.10 through 3.1.2. The vulnerability involves improper input validation that can cause browserifying code to silently generate zero-filled cryptographic keys instead of proper ones, particularly when used in environments different from Node.js or test settings.

    So pretty bad. 8.1 out of ten for setting your crypto keys to match the US nuclear arsenal in the 80s

  • koper@feddit.nl
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    1
    ·
    13 days ago

    Paywalled.

    • Kid@sh.itjust.worksOPM
      link
      fedilink
      English
      arrow-up
      3
      ·
      13 days ago

      Sorry. It was not paywalled for me when I first saw. More info from different source: https://feedly.com/cve/CVE-2025-6545

    • Kid@sh.itjust.worksOPM
      link
      fedilink
      English
      arrow-up
      1
      ·
      13 days ago

      https://feedly.com/cve/CVE-2025-6547

Cybersecurity@sh.itjust.works

cybersecurity@sh.itjust.works

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !cybersecurity@sh.itjust.works

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

  • Be respectful. Everyone should feel welcome here.
  • No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
  • No Ads / Spamming.
  • No pornography.

Community Rules

  • Idk, keep it semi-professional?
  • Nothing illegal. We’re all ethical here.
  • Rules will be added/redefined as necessary.

If you ask someone to hack your “friends” socials you’re just going to get banned so don’t do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 75 users / day
  • 398 users / week
  • 1.25K users / month
  • 2.75K users / 6 months
  • 1 local subscriber
  • 7.74K subscribers
  • 810 Posts
  • 762 Comments
  • Modlog
  • mods:
  • Kid@sh.itjust.works
  • Lanky_Pomegranate530@midwest.social
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org