The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions defaults to a low work factor, which allows attackers to quickly crack password hashes.
References
Configurations
No configuration.
History
20 Feb 2024, 19:50
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
20 Feb 2024, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-20 10:15
Updated : 2024-02-20 19:50
NVD link : CVE-2024-25607
Mitre link : CVE-2024-25607
CVE.ORG link : CVE-2024-25607
JSON object : View
Products Affected
No product.
CWE
CWE-916
Use of Password Hash With Insufficient Computational Effort