bcrypt password hashing in Botan before 2.1.0 does not...
High severity
Unreviewed
Published
Nov 3, 2023
to the GitHub Advisory Database
•
Updated Nov 22, 2023
Description
Published by the National Vulnerability Database
Nov 3, 2023
Published to the GitHub Advisory Database
Nov 3, 2023
Last updated
Nov 22, 2023
bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.
References