CVE-2024-41260
High
NetBird uses a static initialization vector (IV) in github.com/netbirdio/netbird
NetBird uses a static initialization vector (IV) in github.com/netbirdio/netbird
Exploit probability
0.5%
Published
August 13, 2024
Required by
Not available
Last source change
March 3, 2026
02 / AFFECTED SOFTWARE
Affected packages
04 / EVIDENCE
Source records
Open Source Vulnerabilities
GO-2024-3057
View original source
NetBird uses a static initialization vector (IV) in github.com/netbirdio/netbird
Open Source Vulnerabilities
GHSA-9v35-4xcr-w9ph
View original source
A static initialization vector (IV) in the encrypt function of netbird management's service from v0.23.2 to v0.29.1 allows attackers to obtain sensitive information (email addresses) when in possession of the audit events database.
05 / REFERENCES
Further evidence
- https://gist.github.com/nyxfqq/92232108ac153e95d538bb17fc5ad636
- https://github.com/advisories/GHSA-9v35-4xcr-w9ph
- https://github.com/netbirdio/netbird/commit/cf6210a6f42355e88c422c624376f6fcdaea6729
- https://github.com/netbirdio/netbird/issues/2246
- https://github.com/netbirdio/netbird/pull/2569
- https://nvd.nist.gov/vuln/detail/CVE-2024-41260
- https://github.com/github/advisory-database/pull/5714
- https://github.com/netbirdio/netbird