Back

MEDIUM

springframework: BCrypt skips salt rounds for work factor of 31

Published May 19, 2022

Description

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.

Affected products

Remediation

No remediation recorded yet.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published May 19, 2022
Updated Aug 3, 2024
Reserved Jan 10, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 17, 2022
ENISA EUVD
Assigner vmware
Published May 19, 2022
Updated Aug 3, 2024
Exploited since n/a
EUVD-2022-5665 GHSA-WX54-3278-M5G4