Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1maDMyLTM1dzItcnhjY83O8g

Use of Password Hash With Insufficient Computational Effort in Apache Derby

The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 performs a transformation that reduces the size of the set of inputs to SHA-1, which produces a small search space that makes it easier for local and possibly remote attackers to crack passwords by generating hash collisions, related to password substitution.

Permalink: https://github.com/advisories/GHSA-fh32-35w2-rxcc
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1maDMyLTM1dzItcnhjY83O8g
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 2 years ago
Updated: 7 months ago


Identifiers: GHSA-fh32-35w2-rxcc, CVE-2009-4269
References: Repository: https://github.com/apache/derby
Blast Radius: 0.0

Affected Packages

maven:org.apache.derby:derby
Dependent packages: 2,009
Dependent repositories: 22,059
Downloads:
Affected Version Ranges: <= 10.5.3.01
Fixed in: 10.6.1.0
All affected versions:
All unaffected versions: