GHSA-v427-c49j-8w6x

    Dashboard / Vulnerabilities / GHSA-v427-c49j-8w6x

    GHSA-v427-c49j-8w6x

    Published: 23 Nov 2023Last Modified: 10 Sept 2026

    Summary: Cleartext Storage of Sensitive Information in HMAC SHA256 Authentication

    Details: ### Impact **secretKey**, an important key for HMAC SHA256 authentication, was stored in the database in raw form. If a malicious person somehow had access to the data in the database, they could use the key and secretKey for HMAC SHA256 authentication to send requests impersonating that person. ### Patches Upgrade to Shield v1.0.0-beta.8 or later. After upgrading, all existing secret keys must be encrypted. See https://github.com/codeigniter4/shield/blob/develop/UPGRADING.md for details. ### Workarounds None. ### References - https://codeigniter4.github.io/shield/references/authentication/hmac/ ### For more information If you have any questions or comments about this advisory: * Open an issue or discussion in [codeigniter4/shield](https://github.com/codeigniter4/shield) * Email us at [[email protected]](mailto:[email protected])

    Affected packages

    Package

    Name: codeigniter4/shield

    Purl: pkg:composer/codeigniter4/shield

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.0.0-beta.8

    Affected versions

    v1.0.0-beta
    v1.0.0-beta.2
    v1.0.0-beta.3
    v1.0.0-beta.4
    v1.0.0-beta.5
    v1.0.0-beta.6
    v1.0.0-beta.7

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-v427-c49j-8w6x | CVE-DB