Weak credential policy
Description
The application's credential policy does not enforce parameters sufficient to resist guessing attacks.
Impact
Obtain valid credentials through brute-force, dictionary, or credential-stuffing attacks.
Recommendation
- Require passphrases of at least four words or passwords of at least 20 characters. - Reject credentials found in known breach datasets at creation and change time. - Generate temporary credentials with entropy at least equal to that of standard passwords, and force expiry after first use or within a short window (e.g., 15 minutes). - Do not enforce arbitrary periodic expiration without evidence of compromise: per NIST SP 800-63B, mandatory rotation leads users to choose weaker, predictable passwords. Enforce expiration only upon detected compromise.
Threat
Anonymous user from the Internet.
Expected Remediation Time
⏱️ 30 minutes.
Requirements
130 - Limit password lifespan132 - Passphrases with at least 4 words133 - Passwords with at least 20 characters139 - Set minimum OTP length143 - Unique access credentials332 - Prevent the use of breached passwordsRules
Aws Old Credentials EnabledAws Password Expiration UnsafeAws Password Reuse UnsafeAws Old Ssh Public KeysAws Not Requires NumbersAws Not Requires LowercaseAws Not Requires SymbolsAws Old Access KeysAws Min Password Length UnsafeAws Not Requires UppercaseApi Weak Password PolicyJson Yaml Weak Secret ConfigurationTypescript Bcrypt Unsafe Empty PasswordJavascript Jwt Unsafe Empty PasswordJavascript Sequelize Unsafe Empty PasswordJava Empty Password ConnectionC Sharp Weak Credential PolicyTypescript Crypto Unsafe Empty PasswordTerraform Weak Secret ConfigurationGo Mysql Empty Password In DsnTypescript Sequelize Unsafe Empty PasswordTypescript Jwt Unsafe Empty PasswordJavascript Bcrypt Unsafe Empty PasswordJavascript Crypto Unsafe Empty Password