rzo1 opened a new pull request, #3073: URL: https://github.com/apache/tomee/pull/3073
verify() took the algorithm and iteration count from the stored hash without checks, so a weak or tampered hash (e.g. 1 iteration) was accepted. Stored hashes now need a supported PBKDF2 algorithm and at least 1024 iterations, and malformed hashes return false instead of throwing. Setting tomee.security.pbkdf2.allow-weak-parameters=true restores the old behaviour with a warning, which should go into the release notes. Covered by TomEEPbkdf2PasswordHashTest. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
