jasypt before 1.9.2 allows a timing attack against the password hash comparison.
access.redhat.com/errata/RHSA-2017:2546
access.redhat.com/errata/RHSA-2017:2547
access.redhat.com/errata/RHSA-2017:2808
access.redhat.com/errata/RHSA-2017:2809
access.redhat.com/errata/RHSA-2017:2810
access.redhat.com/errata/RHSA-2017:2811
access.redhat.com/errata/RHSA-2017:3141
access.redhat.com/errata/RHSA-2018:0294
nvd.nist.gov/vuln/detail/CVE-2014-9970
sourceforge.net/p/jasypt/code/668