SCA: security update for thinbus-srp (GHSA-8q6v-474h-whgg)

critical Tenable Cloud Security Plugin ID 431684

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Thinbus Javascript Secure Remote Password is a browser SRP6a implementation for zero-knowledge password
authentication. In versions 2.0.0 and below, a protocol compliance bug causes the client to generate a
fixed 252 bits of entropy instead of the intended bit length of the safe prime (defaulted to 2048 bits).
The client public value is being generated from a private value that is 4 bits below the specification.
This reduces the protocol's designed security margin it is now practically exploitable. The servers full
sized 2048 bit random number is used to create the shared session key and password proof. This is fixed in
version 2.0.1. (CVE-2025-54885)

See Also

https://github.com/advisories/GHSA-8q6v-474h-whgg

Plugin Details

Severity: Critical

ID: 431684

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 8/6/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.2

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2025-54885

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.1

Threat Score: 6.9

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/6/2025

Vulnerability Publication Date: 8/6/2025

Reference Information

CVE: CVE-2025-54885

cwe: CWE-331