CVE-2025-22228
20.03.2025, 06:15
BCryptPasswordEncoder.matches(CharSequence,String)will incorrectly return truefor passwords larger than 72 characters as long as the first 72 characters are the same.Enginsight
Common Weakness Enumeration
BCryptPasswordEncoder.matches(CharSequence,String)will incorrectly return truefor passwords larger than 72 characters as long as the first 72 characters are the same.Enginsight