jasypt-spring-boot Insecure Default Config: Deterministic Key Derivation and Weak PBKDF2 Iterations
Security AdvisoryHighjasypt-spring-boot
Affected:
- com.github.ulisesbocchio:jasypt-spring-boot <= 4.0.5-SNAPSHOT
- com.github.ulisesbocchio:jasypt-spring-boot-starter <= 4.0.5-SNAPSHOT
参照 CVE: CVE-2026-9370 · 3.7
文章内图片已隐藏以节省流量 · 升级 Pro 后可见图片及离线存档
本文由本平台从 github.com 自动抓取,经 LLM 流水线清洗、双语翻译。版权归原作者。查看原文。