CVE-2025-22228
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
20/03/2025
Last modified:
25/04/2025
Description
BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.
Impact
Base Score 3.x
7.40
Severity 3.x
HIGH