If I read the ticket correctly, this is preventing bcrypt of incoming credentials from causing a DOS? I think that’s reasonable to backport. If we want to be conservative it could be backported with added code that keeps the current behavior by default? On Nov 5, 2024, at 7:43 AM, Josh McKenzie <jmcken...@apache.org> wrote:
|
- Backporting CASSANDRA-17812 to 4.x Štefan Miklošovič
- Re: Backporting CASSANDRA-17812 to 4.x Mick Semb Wever
- Re: Backporting CASSANDRA-17812 to 4.x Josh McKenzie
- Re: Backporting CASSANDRA-17812 to 4.x J. D. Jordan
- Re: Backporting CASSANDRA-17812 to 4... Štefan Miklošovič
- Re: Backporting CASSANDRA-17812... Bernardo Botella