Scala Short Gcm Auth Tag
Description
Detects the use of short authentication tags (less than 96 bits) in GCM (Galois/Counter Mode) encryption in Scala applications. Short authentication tags significantly weaken the cryptographic security by making it easier for attackers to forge authenticated ciphertext, potentially leading to data tampering and unauthorized access.
Detection Strategy
• Scans Scala source code files that import javax.crypto library for cryptographic operations
• Identifies calls to encryption initialization methods that configure GCM cipher specifications
• Extracts and analyzes the cipher specification parameter to determine the authentication tag length
• Reports a vulnerability when the GCM authentication tag is configured to be shorter than the recommended 96-bit minimum length
• Focuses on cipher initialization points where developers explicitly set authentication tag parameters that compromise security
Vulnerable code example
import javax.crypto.Cipher
import javax.crypto.spec.GCMParameterSpec
import javax.crypto.spec.SecretKeySpec
object VulnerableGCM {
def encrypt(keySpec: SecretKeySpec, data: Array[Byte]): Array[Byte] = {
val iv = new Array[Byte](12)
...✅ Secure code example
import java.security.SecureRandom
import javax.crypto.Cipher
import javax.crypto.spec.GCMParameterSpec
import javax.crypto.spec.SecretKeySpec
object SecureGCM {
def encrypt(keySpec: SecretKeySpec, data: Array[Byte]): Array[Byte] = {
val iv = new Array[Byte](12)...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.