Elixir prior to and including 0.7.1 uses Blowfish in CFB mode without constructing a unique initialization vector (IV), which makes it easier for context-dependent users to obtain sensitive information and decrypt the database. A patch has been attached to the initial advisory to mitigate this vulnerability.
{
"github_reviewed_at": "2024-05-01T11:17:51Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-327"
],
"severity": "HIGH",
"nvd_published_at": "2012-08-26T21:55:00Z"
}