logo

Database

Scala Predictable Iv Nonce Source

Description

This vulnerability detector identifies cryptographic implementations that use predictable initialization vectors (IVs) or nonces in Scala code. Predictable IVs compromise encryption security by making encrypted data patterns observable and potentially allowing attackers to decrypt sensitive information or perform chosen-plaintext attacks.

Weakness:

395 - Insecure generation of random numbers - Static IV

Category: Functionality Abuse

Detection Strategy

    • Scans Scala source code files that import the javax.crypto library for cryptographic operations

    • Identifies cipher initialization calls (init method invocations) on Cipher objects created through Cipher.getInstance()

    • Verifies the cipher is being configured for encryption mode (not decryption)

    • Checks if an AlgorithmParameterSpec argument is provided that constructs predictable initialization vectors or nonces

    • Reports vulnerability when encryption ciphers use deterministic or static IV/nonce values instead of cryptographically secure random values

Vulnerable code example

import javax.crypto.Cipher
import javax.crypto.spec.IvParameterSpec
import javax.crypto.spec.SecretKeySpec

def encrypt(data: Array[Byte], password: String): Array[Byte] = {
  val cipher = Cipher.getInstance("AES/CBC/PKCS5Padding")
  val key = new SecretKeySpec(password.getBytes, "AES")
  ...

✅ Secure code example

import java.security.SecureRandom
import javax.crypto.Cipher
import javax.crypto.spec.IvParameterSpec
import javax.crypto.spec.SecretKeySpec

def encrypt(data: Array[Byte], password: String): Array[Byte] = {
  val cipher = Cipher.getInstance("AES/CBC/PKCS5Padding")
  val key = new SecretKeySpec(password.getBytes, "AES")...