CVE-2025-6545

Vulnerability

CVE-2025-6545

pbkdf2: pbkdf2 silently returns predictable key material

ecosystem: redhat:7, redhat:8

A flaw was found in the npm pbkdf2 library, allowing signature spoofing. When executing in javascript engines other than Nodejs or Nodejs when importing pbkdf2/browser, certain algorithms will silently fail and return invalid data. The return values are predictable, which undermines the security guarantees of the package.

References
severityI
Important

type: vendor

source: secalert@redhat.com

CVSS3.1
8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AVNetwork
ACHigh
PRNone
UINone
SNot Changed
CHigh
IHigh
AHigh

source: secalert@redhat.com

 CWE
CWE-20

Improper Input Validation

source: secalert@redhat.com

published: 2025-06-23 18:41:18

modified: 2025-07-15 14:14:00

Detection

OR

 unfixed

 

firefox

package type: source

type: version
 unfixed

 

thunderbird

package type: source

type: version

tag: rhel-7-extras-including-unpatched:37f3937f-8123-7add-abf7-cf9f6a1e892e

OR

 unfixed

 

mozjs60

package type: source

type: version

tag: rhel-8-including-unpatched:882fc17d-ce8d-8230-a24e-b80dc059e3d7

Data Sources

  • RedHat Enterprise Linux CSAF VEX

    redhat-vex

VulsFutureVuls|GitHub