rzo1 opened a new pull request, #3073:
URL: https://github.com/apache/tomee/pull/3073

   verify() took the algorithm and iteration count from the stored hash without 
checks, so a weak or tampered hash (e.g. 1 iteration) was accepted. Stored 
hashes now need a supported PBKDF2 algorithm and at least 1024 iterations, and 
malformed hashes return false instead of throwing. Setting 
tomee.security.pbkdf2.allow-weak-parameters=true restores the old behaviour 
with a warning, which should go into the release notes. Covered by 
TomEEPbkdf2PasswordHashTest.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to