USN-6753-1: CryptoJS vulnerability
25 April 2024
CryptoJS could be made to expose sensitive information.
Releases
Packages
- cryptojs - collection of cryptographic algorithms implemented in JavaScript
Details
Thomas Neil James Shadwell discovered that CryptoJS was using an insecure
cryptographic default configuration. A remote attacker could possibly use
this issue to expose sensitive information.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.04
-
libjs-cryptojs
-
3.1.2+dfsg-3ubuntu0.22.04.1~esm1
Available with Ubuntu Pro
Ubuntu 20.04
Ubuntu 18.04
-
libjs-cryptojs
-
3.1.2+dfsg-2ubuntu0.18.04.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
libjs-cryptojs
-
3.1.2+dfsg-2ubuntu0.16.04.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.