Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35618
HistoryMay 20, 2022 - 4:01 a.m.

Integer Overflow

2022-05-2004:01:08
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

0.002 Low

EPSS

Percentile

51.7%

org.springframework.security:spring-security-crypto is vulnerable to integer overflows. The encoder does not perform any salt rounds when the BCrypt class is used with the maximum work factor(31), allowing a local authenticated attacker to cause an integer overflow error resulting in the attacker gaining access to sensitive user information.