Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/lf-edge/eve
  4. ›
  5. GHSA-hx74-4wmc-fwvf

GHSA-hx74-4wmc-fwvf: Duplicate Advisory: EVE Has Partially Predetermined Vault Key

September 21, 2023 (updated February 4, 2026)

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-wc42-fcjp-v8vq. This link is maintained to preserve external references.

Original Description

Due to the implementation of “deriveVaultKey”, prior to version 7.10, the generated vault key would always have the last 16 bytes predetermined to be “arfoobarfoobarfo”.

This issue happens because “deriveVaultKey” calls “retrieveCloudKey” (which will always return “foobarfoobarfoobarfoobarfoobarfo” as the key), and then merges the 32byte randomly generated key with this key (by takeing 16bytes from each, see “mergeKeys”).

This makes the key a lot weaker.

This issue does not persist in devices that were initialized on/after version 7.10, but devices that were initialized before that and updated to a newer version still have this issue.

Roll an update that enforces the full 32bytes key usage.

References

  • asrg.io/security-advisories/cve-2023-43637
  • asrg.io/security-advisories/vault-key-partially-predetermined
  • github.com/advisories/GHSA-hx74-4wmc-fwvf
  • nvd.nist.gov/vuln/detail/CVE-2023-43637

Code Behaviors & Features

Detect and mitigate GHSA-hx74-4wmc-fwvf with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.0.0-20220310190112-c0c966dc31e2

Fixed versions

  • 0.0.0-20220310190112-c0c966dc31e2

Solution

Upgrade to version 0.0.0-20220310190112-c0c966dc31e2 or above.

Impact 7.8 HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-321: Use of Hard-coded Cryptographic Key
  • CWE-798: Use of Hard-coded Credentials

Source file

go/github.com/lf-edge/eve/GHSA-hx74-4wmc-fwvf.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 05 Feb 2026 00:18:39 +0000.