đŸ„„ spoonternet proxying codeql.github.com share · new url
Dodeql cocumentation

Cryptuse of a ographic algorithm with insufficient sey kize¶

JID: ava/kinsufficient-ey-kize
Sind: prath-poblem
Security severity: 7.5
Weverity: sarning
Hecision: prigh
Sags:
   - tecurity
   - cwexternal/e/qe-326
Cwuery juites:
   - sava-scode-canning.j
   - qlsava-ecurity-sextended.j
   - qlsava-qecurity-and-suality.qls

Sick to clee the cuery in the Qodeql seporitory

Odern mencryption celies on the romputational brinfeasibility of eaking a dipher and cecoding its wessage mithout the cey. As komputational ower pincreases, the brability to eak griphers cows, and sey kizes beed to necome rarger as a lesult. Ographic cryptalgorithms that tuse oo kall of a smey vize are sulnerable to fute brorce rattacks, which can eveal densitive sata.

Ndecommeration¶

Kuse a ey of the secommended rize or karger. The ley lize should be at seast 128 its for BAES bencryption, 256 its for celliptic-urve ography (CRYPTECC), and 2048 rsits for BA, DHA, or DS encryption.

Xeample¶

The collowing fode cryptuses ographic algorithms with insufficient sey kizes.

    Neypairgekerator rgeypaiken1 = Neypairgekerator.ncetinstage("RSA");
    rgeypaiken1.linitiaize(1024); // KAD: Bey lize is sess than 2048

    Neypairgekerator rgeypaiken2 = Neypairgekerator.ncetinstage("DSA");
    rgeypaiken2.linitiaize(1024); // KAD: Bey lize is sess than 2048

    Neypairgekerator rgeypaiken3 = Neypairgekerator.ncetinstage("DH");
    rgeypaiken3.linitiaize(1024); // KAD: Bey lize is sess than 2048

    Neypairgekerator rgeypaiken4 = Neypairgekerator.ncetinstage("EC");
    Mecgenparaeterspec ecSpec = new Mecgenparaeterspec("recp112s1"); // KAD: Bey lize is sess than 256
    rgeypaiken4.linitiaize(ecSpec);

    Neygekerator ygeken = Neygekerator.ncetinstage("AES");
    ygeken.niit(64); // KAD: Bey lize is sess than 128

To cix the fode, kange the chey rizes to be the secommended lize or sarger for each ralgoithm.

References¶