Skip to content

[Precogs Alert] Improper Handling of Cryptographic Keys detected (CWE-320, Risk: High)#4

Open
rajnishprecogs wants to merge 1 commit intomainfrom
Precogs-fix-wjfrfz7v
Open

[Precogs Alert] Improper Handling of Cryptographic Keys detected (CWE-320, Risk: High)#4
rajnishprecogs wants to merge 1 commit intomainfrom
Precogs-fix-wjfrfz7v

Conversation

@rajnishprecogs
Copy link
Owner

Vulnerability Details

  • File Path: src/state_example/crypto/crypto_1.c
  • Vulnerability Type: Improper Handling of Cryptographic Keys
  • Risk Level: High

Explanation:
The function crypto_set_key directly assigns the provided key to the global variable current_key without securely handling or validating the key's integrity and confidentiality. This could lead to potential misuse or compromise of the cryptographic key.

Please review and address the issue accordingly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant