SCA: security update for @dfinity/auth-client, @dfinity/identity (GHSA-c9vv-fhgv-cjc3)

critical Tenable Cloud Security Plugin ID 413811

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with
an optional param to provide a 32 byte seed value, which will then be used as the secret key. When no seed
value is provided, it is expected that the library generates the secret key using secure randomness.
However, a recent change broke this guarantee and uses an insecure seed for key pair generation. Since the
private key of this identity (535yc-uxytb-gfk7h-tny7p-vjkoe-i4krp-3qmcl-uqfgr-cpgej-yqtjq-rqe) is
compromised, one could lose funds associated with the principal on ledgers or lose access to a canister
where this principal is the controller. (CVE-2024-1631)

Solution

Update the @dfinity/auth-client library and its related packages to version 1.0.1 or later.

See Also

https://github.com/advisories/GHSA-c9vv-fhgv-cjc3

Plugin Details

Severity: Critical

ID: 413811

Version: Revision 1.9

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.37

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2024-1631

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2/21/2024

Vulnerability Publication Date: 2/21/2024

Reference Information

CVE: CVE-2024-1631