Insecure Cryptography Algorithm
Affecting org.ojalgo:ojalgo artifact, versions [0,48.3.2)
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Insecure Cryptography Algorithm. It uses the unsafe MD5 cryptographic algorithm to store passwords.
Remediation
Upgrade org.ojalgo:ojalgo
to version 48.3.2 or higher.
References
CVSS Score
6.8
medium severity
-
Attack VectorNetwork
-
Attack ComplexityHigh
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeChanged
-
ConfidentialityHigh
-
IntegrityNone
-
AvailabilityNone
- Credit
- Unknown
- CWE
- CWE-310
- Snyk ID
- SNYK-JAVA-ORGOJALGO-1028059
- Disclosed
- 31 Oct, 2020
- Published
- 07 Jan, 2021