Description
jasypt before 1.9.2 allows a timing attack against the password hash comparison.
Remediation
References
https://sourceforge.net/p/jasypt/code/668/
http://www.securitytracker.com/id/1039744
https://access.redhat.com/errata/RHSA-2017:3141
https://access.redhat.com/errata/RHSA-2017:2811
https://access.redhat.com/errata/RHSA-2017:2810
https://access.redhat.com/errata/RHSA-2017:2809
https://access.redhat.com/errata/RHSA-2017:2808
https://access.redhat.com/errata/RHSA-2017:2547
https://access.redhat.com/errata/RHSA-2017:2546
https://access.redhat.com/errata/RHSA-2018:0294
http://www.securitytracker.com/id/1040360
Related Vulnerabilities
CVE-2022-31018 Vulnerability in maven package com.typesafe.play:play_2.13
CVE-2022-45385 Vulnerability in maven package org.jenkins-ci.plugins:dockerhub-notification
CVE-2022-31129 Vulnerability in maven package org.webjars.npm:moment
CVE-2022-27772 Vulnerability in maven package org.springframework.boot:spring-boot