Crypto CipherIntegrity

The ciphertext produced is susceptible to alteration by an adversary. This mean that the cipher provides no way to detect that the data has been tampered with. If the ciphertext can be controlled by an attacker, it could be altered without detection.

IndexedPublic repositoryHighMedium confidenceVerifiedLGPL-3.0-onlyKotlin
greprules fetch gitlab-sast-rules-lgpl-kotlin-crypto-rule-cipherintegrity --engine opengrep

Description

The ciphertext produced is susceptible to alteration by an adversary. This mean that the cipher provides no way to detect that the data has been tampered with. If the ciphertext can be controlled by an attacker, it could be altered without detection.