Vulnerability Description
WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backups. This is arguably a Principle of Least Surprise violation because "the user likely wanted to encrypt all file activity."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wal-G Project | Wal-G | < 1.1 |
Related Weaknesses (CWE)
References
- https://github.com/wal-g/wal-g/commit/cadf598e1c2a345915a21a44518c5a4d5401e2e3PatchThird Party Advisory
- https://github.com/wal-g/wal-g/pull/1062PatchThird Party Advisory
- https://github.com/wal-g/wal-g/commit/cadf598e1c2a345915a21a44518c5a4d5401e2e3PatchThird Party Advisory
- https://github.com/wal-g/wal-g/pull/1062PatchThird Party Advisory
FAQ
What is CVE-2021-38599?
CVE-2021-38599 is a vulnerability with a CVSS score of 7.5 (HIGH). WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backu...
How severe is CVE-2021-38599?
CVE-2021-38599 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-38599?
Check the references section above for vendor advisories and patch information. Affected products include: Wal-G Project Wal-G.