2.9.2.SP1
7 years ago
2 days ago
Known vulnerabilities in the org.wildfly.security:wildfly-elytron-password-impl package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Improper Handling of Alternate Encoding in its password normalization, which applies Unicode NFKC (compatibility) normalization before hashing and so folds fullwidth and other compatibility characters to their ASCII equivalents. An attacker with access to the stored password hashes can shrink the effective keyspace and test ASCII dictionary candidates against passwords originally set with compatibility characters, since distinct inputs such as How to fix Improper Handling of Alternate Encoding? A fix was pushed into the | [0,) |