Description
WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backups. This is arguably a Principle of Least Surprise violation because "the user likely wanted to encrypt all file activity."
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2117 | WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backups. This is arguably a Principle of Least Surprise violation because "the user likely wanted to encrypt all file activity." |
Github GHSA |
GHSA-vrmr-f2qh-3hhf | Improper use of cryptographic key in wal-g |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T01:44:23.479Z
Reserved: 2021-08-12T00:00:00.000Z
Link: CVE-2021-38599
No data.
Status : Modified
Published: 2021-08-12T16:15:10.533
Modified: 2024-11-21T06:17:38.643
Link: CVE-2021-38599
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA