PT-2017-6415 · Jasypt · Jasypt

Published

2017-05-21

·

Updated

2022-05-14

·

CVE-2014-9970

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions jasypt versions prior to 1.9.2
Description The issue allows a timing attack against the password hash comparison.
Recommendations For versions prior to 1.9.2, update to version 1.9.2 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-9970
GHSA-R5C2-RXH2-F5H2
RHSA-2017:2808
RHSA-2017:2809
RHSA-2017:2811
RHSA-2017:2904
RHSA-2017:2905
RHSA-2017:3141

Affected Products

Jasypt