Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28637
HistoryDec 18, 2020 - 8:45 a.m.

Insecure Password Matching

2020-12-1808:45:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.006 Low

EPSS

Percentile

77.7%

bouncycastle is vulnerable to incorrect password matching. An attacker is able to pass an incorrect password and gets it accepted as a correct one due to a comparison error in the function OpenBSDBCrypt.checkPassword().

References