Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-22228

Опубликовано: 20 мар. 2025
Источник: redhat
CVSS3: 7.4

Описание

BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.

A flaw was found in the spring-security-core password encoder. This vulnerability allows incorrect password matching via input manipulation.

Меры по смягчению последствий

Red Hat Product Security does not have a recommended mitigation at this time.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2spring-security-coreOut of support scope
Red Hat build of Quarkusquarkus-bomNot affected
Red Hat Data Grid 8spring-security-coreWill not fix
Red Hat Fuse 7org.apache.servicemix.bundles.spring-security-coreWill not fix
Red Hat Fuse 7spring-security-coreWill not fix
Red Hat Integration Camel K 1spring-security-coreWill not fix
Red Hat JBoss Enterprise Application Platform 7spring-security-coreNot affected
Red Hat JBoss Enterprise Application Platform 8spring-security-coreNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packspring-security-coreNot affected
Red Hat Process Automation 7spring-security-coreWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2353507spring-security-core: Spring Security BCryptPasswordEncoder does not enforce maximum password length

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
nvd
9 месяцев назад

BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.

CVSS3: 7.4
debian
9 месяцев назад

BCryptPasswordEncoder.matches(CharSequence,String)will incorrectly ret ...

CVSS3: 7.4
github
9 месяцев назад

Spring Security Does Not Enforce Password Length

7.4 High

CVSS3