Описание
BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.
EPSS
Процентиль: 31%
0.00119
Низкий
7.4 High
CVSS3
Дефекты
CWE-287
Связанные уязвимости
CVSS3: 7.4
redhat
11 месяцев назад
BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.
CVSS3: 7.4
debian
11 месяцев назад
BCryptPasswordEncoder.matches(CharSequence,String)will incorrectly ret ...
EPSS
Процентиль: 31%
0.00119
Низкий
7.4 High
CVSS3
Дефекты
CWE-287