Property
Languagejavascript
Severityhigh
CWECWE-310: CWE CATEGORY: Cryptographic Issues
OWASPA02:2021 - Cryptographic Failures
Confidence LevelHigh
Impact LevelMedium
Likelihood LevelHigh

Description#

The ‘final’ call of a Decipher object checks the authentication tag in a mode for authenticated encryption. Failing to call ‘final’ will invalidate all integrity guarantees of the released ciphertext.