Description
jasypt before 1.9.2 allows a timing attack against the password hash comparison.
Remediation
References
http://www.securitytracker.com/id/1039744
http://www.securitytracker.com/id/1040360
https://access.redhat.com/errata/RHSA-2017:2546
https://access.redhat.com/errata/RHSA-2017:2547
https://access.redhat.com/errata/RHSA-2017:2808
https://access.redhat.com/errata/RHSA-2017:2809
https://access.redhat.com/errata/RHSA-2017:2810
https://access.redhat.com/errata/RHSA-2017:2811
https://access.redhat.com/errata/RHSA-2017:3141
https://access.redhat.com/errata/RHSA-2018:0294
https://sourceforge.net/p/jasypt/code/668/
Related Vulnerabilities
CVE-2021-43571 Vulnerability in npm package starkbank-ecdsa
CVE-2021-22112 Vulnerability in maven package org.springframework.security:spring-security-core
CVE-2022-28820 Vulnerability in maven package com.adobe.acs:acs-aem-commons
CVE-2023-50572 Vulnerability in maven package org.jline:jline-console
CVE-2022-1291 Vulnerability in maven package org.webjars.bowergithub.hhurz:tableexport.jquery.plugin