PT-2026-106490 · Cloak · Cloak
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
danielberkompas cloak versions 0.1.0-pre and later
Description
The software relies on encryption of security-relevant inputs without integrity checking. Specifically,
Cloak.Ciphers.AES.CTR and Cloak.Ciphers.Deprecated.AES.CTR use AES-256 in CTR mode, which is a stream cipher, and store the key tag, IV, and ciphertext without a Message Authentication Code (MAC). The decrypt/2 function only verifies the key tag and minimum length before returning the plaintext.An attacker with write access to the encrypted store—obtained through methods such as SQL injection or a compromised replica—who knows or can guess the stored plaintext can perform bit flipping. By XORing a value into the stored ciphertext, the attacker can change the decrypted plaintext to a chosen value of the same length. The application will then decrypt and trust this forged value without error.
Recommendations
Configure the vault to use
Cloak.Ciphers.AES.GCM as the default cipher and re-encrypt existing values.
Remove Cloak.Ciphers.AES.CTR and Cloak.Ciphers.Deprecated.AES.CTR from the vault configuration to prevent the decryption of ciphertext in CTR format.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloak