An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-12-18T00:52:48
Updated: 2024-08-04T16:33:56.942Z
Reserved: 2020-11-02T00:00:00
Link: CVE-2020-28052
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-12-18T01:15:12.587
Modified: 2023-11-07T03:21:07.073
Link: CVE-2020-28052
Redhat