{"id":"GHSA-35m5-8cvj-8783","summary":"Improper hashing in enrocrypt","details":"### Impact\nThe vulnerability is we used MD5 hashing Algorithm In our hashing file. If anyone who is a beginner(and doesn't know about hashes)  can face problems as MD5 is considered a Insecure Hashing Algorithm. \n\n### Patches\nThe vulnerability is patched in v1.1.4 of the product, the users can upgrade to version 1.1.4.\n\n### Workarounds\nIf u specifically want a version and don't want to upgrade, you can remove the `MD5` hashing function from the file `hashing.py` and this vulnerability will be gone\n\n### References\nhttps://www.cybersecurity-help.cz/vdb/cwe/916/\nhttps://www.cybersecurity-help.cz/vdb/cwe/327/\nhttps://www.cybersecurity-help.cz/vdb/cwe/328/\nhttps://www.section.io/engineering-education/what-is-md5/\nhttps://www.johndcook.com/blog/2019/01/24/reversing-an-md5-hash/\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [**Enrocrypt's Official Repo**](http://www.github.com/Morgan-Phoenix/EnroCrypt)\n* Create a Discussion in  [**Enrocrypt's Official Repo**](http://www.github.com/Morgan-Phoenix/EnroCrypt)\n","aliases":["CVE-2021-39182","PYSEC-2021-385"],"modified":"2026-07-08T06:28:04.810532602Z","published":"2021-11-10T16:28:46Z","database_specific":{"cwe_ids":["CWE-326","CWE-327","CWE-328","CWE-916"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-11-08T18:58:04Z","nvd_published_at":"2021-11-08T15:15:00Z"},"references":[{"type":"WEB","url":"https://github.com/Morgan-Phoenix/EnroCrypt/security/advisories/GHSA-35m5-8cvj-8783"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-39182"},{"type":"WEB","url":"https://github.com/Morgan-Phoenix/EnroCrypt/commit/e652d56ac60eadfc26489ab83927af13a9b9d8ce"},{"type":"PACKAGE","url":"https://github.com/Morgan-Phoenix/EnroCrypt"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/enrocrypt/PYSEC-2021-385.yaml"}],"affected":[{"package":{"name":"enrocrypt","ecosystem":"PyPI","purl":"pkg:pypi/enrocrypt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.4"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.1.0","1.1.1","1.1.2","1.1.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-35m5-8cvj-8783/GHSA-35m5-8cvj-8783.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}