← Back to CVE List

CVE-2021-38599

Published: 2021-08-12T16:15Z
Last Modified: 2024-11-21T06:17Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is used, silently ignores the libsodium encryption key and uploads cleartext backups. This is arguably a Principle of Least Surprise violation because "the user likely wanted to encrypt all file activity." > MITRE Terms of Use apply – see LICENSE‑MITRE.txt