logo

Database

Sensitive information sent insecurely In org.jasypt:jasypt

Description

Exposure of Sensitive Information to an Unauthorized Actor in Apache Jasypt jasypt before 1.9.2 allows a timing attack against the password hash comparison.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions