In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade Chainguard
camunda-zeebe-8.6
to version 8.6.12-r1 or higher.
Note: Versions mentioned in the description apply only to the upstream camunda-zeebe-8.6
package and not the camunda-zeebe-8.6
package as distributed by Chainguard
.
See How to fix?
for Chainguard
relevant fixed versions and status.
BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.