Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40691
HistoryMay 26, 2023 - 3:06 a.m.

Weak Password Requirements

2023-05-2603:06:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
password policy
vulnerability
brute force

EPSS

0.04

Percentile

92.1%

org.apache.inlong is vulnerable to Weak Password Requirements. The vulnerability is due to a lack of a password policy, such as allowing a simple password (with any character or symbol) because the UserRequest.java does not properly limit the length, which would allow an attacker to brute force the user’s password.

EPSS

0.04

Percentile

92.1%