PT-2021-22237 · Wal-G · Wal-G

Sehrope

·

Published

2021-08-12

·

Updated

2022-07-12

·

CVE-2021-38599

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WAL-G versions prior to 1.1
Description The issue arises when a non-libsodium build of WAL-G is used, causing it to silently ignore the libsodium encryption key and upload backups in cleartext. This behavior is considered a violation of the Principle of Least Surprise, as users likely intend to encrypt all file activity.
Recommendations For versions prior to 1.1, update to version 1.1 or later to ensure that backups are properly encrypted. As a temporary workaround, consider avoiding the use of non-libsodium builds until a secure version is available.

Fix

Improper Check for Exceptional Conditions

Insecure Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-38599
GHSA-VRMR-F2QH-3HHF

Affected Products

Wal-G