CVE-2023-46233
crypto-js Weak PBKDF2 Iterations Exposes Sensitive Data
Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.
The crypto-js JavaScript library has a critical vulnerability in its PBKDF2 function due to using weak cryptographic standards, significantly reducing its security for password protection and signature generation. If an application uses this library and is reachable, sensitive data could be compromised. Confirming the