{"id":"CVE-2025-68701","aliases":["GHSA-crxp-chh4-9ghp"],"url":"https://o3.security/vulnerability/CVE-2025-68701","summary":"Jervis has Deterministic AES IV Derivation from Passphrase","details":"### Vulnerability\n\nhttps://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L866-L874\n\nhttps://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L891-L900\n\nSame passphrase + same plaintext = same ciphertext (IV reuse)\n\n### Impact\n\nSeverity is considered low for internal uses of this library but if there's any consumer using these methods directly then this is considered high.\n\nSignificant reduction in the security of the encryption scheme. Pattern analysis becomes possible.\n\n### Patches\n\nRandom IV will be generated and prepended to the ciphertext.\n\nUpgrade to Jervis 2.2.\n\n### Workarounds\n\nNone","published":"2026-01-13T19:21:30.074Z","modified":"2026-08-12T03:51:09.521043635Z","cvss":null,"epss":{"score":0.00237,"percentile":0.1493,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"net.gleske:jervis","fixedVersion":"2.2"}],"fix":{"url":"https://github.com/samrocketman/jervis/commit/c3981ff71de7b0f767dfe7b37a2372cb2a51974a","label":"samrocketman/jervis@c3981ff"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68701.json"},{"type":"ADVISORY","url":"https://github.com/samrocketman/jervis/security/advisories/GHSA-crxp-chh4-9ghp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68701"},{"type":"FIX","url":"https://github.com/samrocketman/jervis/commit/c3981ff71de7b0f767dfe7b37a2372cb2a51974a"},{"type":"PACKAGE","url":"https://github.com/samrocketman/jervis"},{"type":"WEB","url":"https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L866-L874"},{"type":"WEB","url":"https://github.com/samrocketman/jervis/blob/157d2b63ffa5c4bb1d8ee2254950fd2231de2b05/src/main/groovy/net/gleske/jervis/tools/SecurityIO.groovy#L891-L900"},{"type":"WEB","url":"http://github.com/samrocketman/jervis/commit/c3981ff71de7b0f767dfe7b37a2372cb2a51974a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:09.521043635Z"}}