Use of a One-Way Hash with a Predictable Salt Affecting com.github.ulisesbocchio:jasypt-spring-boot package, versions [3.0.4,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.2% (11th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-COMGITHUBULISESBOCCHIO-16873884
  • published28 May 2026
  • disclosed24 May 2026
  • creditdntyfate

Introduced: 24 May 2026

CVE-2026-9370  (opens in a new tab)
CWE-760  (opens in a new tab)

How to fix?

There is no fixed version for com.github.ulisesbocchio:jasypt-spring-boot.

Overview

Affected versions of this package are vulnerable to Use of a One-Way Hash with a Predictable Salt in the getSecretKeySaltGenerator function of the Password Hash Handler component. An attacker can compromise the confidentiality of hashed secrets by exploiting the use of a predictable salt in password hashing, allowing easier brute force or precomputed attacks.

CVSS Base Scores

version 4.0
version 3.1