VDB
Sign up
MEDIUM

GHSA-9h6p-92jq-888x

Integer Overflow or Wraparound in JBCrypt

Quick fix

GHSA-9h6p-92jq-888x — org.mindrot:jbcrypt: upgrade to the fixed version with the command below.

# pom.xml: bump <version>0.4</version> for org.mindrot:jbcrypt

Details

Integer overflow in the crypt_raw method in the key-stretching implementation in JBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.mindrot:jbcrypt
Introduced in: 0Fixed in: 0.4
Fix# pom.xml: bump <version>0.4</version> for org.mindrot:jbcrypt

References