Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. Therefore, attackers with a copy of a user's data are able to brute-force the user's encryption key. Users on version 8.0.0 and above are automatically migrated away from the weak encoding on first login. Users should destroy encrypted backups made with versions prior to 8.0.0.
References
Configurations
History
09 Oct 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. Therefore, attackers with a copy of a user's data are able to brute-force the user's encryption key. Users on version 8.0.0 and above are automatically migrated away from the weak encoding on first login. Users should destroy encrypted backups made with versions prior to 8.0.0. |
17 Sep 2024, 13:26
Type | Values Removed | Values Added |
---|---|---|
First Time |
Authenticator
Authenticator authenticator |
|
CWE | CWE-326 | |
CPE | cpe:2.3:a:authenticator:authenticator:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
References | () https://github.com/Authenticator-Extension/Authenticator/commit/17aa2068553db3c3aac081c9ffe393536f33b28b - Patch | |
References | () https://github.com/Authenticator-Extension/Authenticator/security/advisories/GHSA-gv8m-vgp8-q2xr - Vendor Advisory |
04 Sep 2024, 13:05
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
03 Sep 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-03 21:15
Updated : 2024-10-09 15:15
NVD link : CVE-2024-45394
Mitre link : CVE-2024-45394
CVE.ORG link : CVE-2024-45394
JSON object : View
Products Affected
authenticator
- authenticator