CVE-2014-9970 by Fred · 21/05/2017 jasypt before 1.9.2 allows a timing attack against the password hash comparison. Date published : 2017-05-21 https://sourceforge.net/p/jasypt/code/668/ https://access.redhat.com/errata/RHSA-2017:2546 Share this: Share on X (Opens in new window) X Share on Bluesky (Opens in new window) Bluesky Share on Facebook (Opens in new window) Facebook Share on LinkedIn (Opens in new window) LinkedIn Share on Threads (Opens in new window) Threads Share on Mastodon (Opens in new window) Mastodon Similar