Intel

AIKIDO-2024-10566

adyen-java-api-library is vulnerable to Generation of Weak Initialization Vector

Generation of Weak Initialization Vector Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 27, 2024

30

Low Risk

This Affects:

javaadyen-java-api-library
2.2.0 - 32.0.0
Fixed in 32.1.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package suffer from security misconfigurations, including using a static initialization vector (IV), generated only once during application initialization instead of being dynamically generated for each encryption operation. Additionally, the package includes an unencrypted API test endpoint that can be exposed in production environments. An attacker might leverage these vulnerabilities to gather critical information from the application.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

adyen-java-api-library is vulnerable to Generation of Weak Initialization Vector in versions 2.2.0 - 32.0.0.

How to fix this

Upgrade the com.adyen:adyen-java-api-library library to the patch version.