Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22655
HistoryMar 09, 2020 - 4:56 a.m.

Insecure Hashes

2020-03-0904:56:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.002 Low

EPSS

Percentile

53.8%

jpaseto is vulnerable to generating insecure hashes. The vulnerability exists because it has a flawed calculation of hashes using Blake2b.hash since the order of arguments passed to the hash function is wrong, resulting in weak or insecure hashes for v2.local tokens.

0.002 Low

EPSS

Percentile

53.8%

Related for VERACODE:22655