Impact
The flaw lies in Cloak’s AES-CTR cipher where ciphertext is stored without any form of integrity protection. Decrypt/2 validates only the key tag and length, allowing an attacker who can modify encrypted data to flip bits in the ciphertext. Because CTR mode is a stream cipher, any bit changes in the ciphertext produce the same bit changes in the decrypted plaintext, enabling the attacker to produce arbitrary chosen plaintext values. This effectively permits data tampering and could be used to forge tokens, credentials, or any encrypted data stored by the application.
Affected Systems
The vulnerability affects all releases of the Cloak library from version 0.1.0-pre onward for the vendor danielberkompas Cloak.
Risk and Exploitability
With a CVSS score of 8.2 the vulnerability is considered high severity. The EPSS score is not available, and it is not listed in CISA’s KEV catalog. The attack requires write access to the encrypted store, which can be obtained via SQL‑injection, a compromised database replica, or direct file manipulation. Once write access is achieved, the attacker can modify any ciphertext of the same length as the targeted plaintext, causing the application to decrypt it to a value of the attacker’s choosing. The impact spans confidentiality and integrity for data encrypted with the vulnerable cipher and can undermine authentication or authorization mechanisms that rely on those encrypted values.
OpenCVE Enrichment