Fix broken cryptographic primitive protecting a secret in NestJS
A hash, cipher, or random source that cannot carry the weight it has been given: MD5 or SHA-1 over a password, a DES or ECB cipher, or Math.random() producing a token. Each has a drop-in replacement in the standard library, so the fix is small - the cost of not making it is that the protection is decorative.
high likely NestJS CWE-327 / OWASP A02:2021
The vulnerable pattern in NestJS
This finding comes from the NestJS fixture in the owlwarden test suite. This hash is fast, and speed is the attacker's advantage: a commodity GPU tries billions of candidates a second, so a leaked table of these hashes is a leaked table of the values behind them. Password hashing needs a deliberately slow algorithm with a per-value salt.
The corrected handler
Put the hashing behind a provider so every caller gets the same algorithm, rather than each service choosing one.
@Injectable()
export class PasswordService {
async hash(plain: string) {
return await argon2.hash(plain)
}
async verify(hash: string, plain: string) {
return await argon2.verify(hash, plain)
}
}
If you are not using NestJS
Use a slow, salted hash for passwords and a cryptographic random source for tokens. Both are in the Node standard library; neither needs a dependency.
Check your own repository
npx owlwarden scan
npx owlwarden explain weak-crypto
Runs on your machine. No account, no telemetry, no network unless you ask. In CI, SARIF uploads to code scanning and the exit code is the gate.
Other NestJS checks
Rules with a tested NestJS example.
- cors-permissive medium Cross-origin policy accepts any origin
- hardcoded-secret high Credential hardcoded in source
- insecure-cookie medium Cookie set without its protective attributes
- install-lifecycle-script medium Package declares an install-time script
- open-redirect medium Redirect target comes from the caller
- security-headers-missing medium Security headers are not configured
- sensitive-data-logged medium Sensitive data written to a log
- sql-injection high SQL query built by string interpolation
- ssrf high Server fetches a URL the caller controls
- stack-trace-leak high Stack trace leaked in error response