UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing user credentials.
References
Link | Resource |
---|---|
https://blog.jetbrains.com/blog/2019/09/26/jetbrains-security-bulletin-q2-2019/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-10-02 12:15
Updated : 2019-10-08 08:20
NVD link : CVE-2019-12737
Mitre link : CVE-2019-12737
JSON object : View
CWE
CWE-916
Use of Password Hash With Insufficient Computational Effort
Products Affected
jetbrains
- ktor