Description
WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backups. This is arguably a Principle of Least Surprise violation because "the user likely wanted to encrypt all file activity."
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2117 | WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backups. This is arguably a Principle of Least Surprise violation because "the user likely wanted to encrypt all file activity." |
Github GHSA |
GHSA-vrmr-f2qh-3hhf | Improper use of cryptographic key in wal-g |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T01:44:23.479Z
Reserved: 2021-08-12T00:00:00.000Z
Link: CVE-2021-38599
No data.
Status : Modified
Published: 2021-08-12T16:15:10.533
Modified: 2026-06-17T04:02:25.457
Link: CVE-2021-38599
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-754
Improper Check for Unusual or Exceptional Conditions
EUVD
Github GHSA