Candidate: CVE-2014-9970 PublicDate: 2017-05-21 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9970 https://sourceforge.net/p/jasypt/code/668/ Description: jasypt before 1.9.2 allows a timing attack against the password hash comparison. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_jasypt: upstream_jasypt: released (1.9.2-1) precise/esm_jasypt: DNE trusty_jasypt: ignored (reached end-of-life) trusty/esm_jasypt: DNE (trusty was needed) vivid/stable-phone-overlay_jasypt: DNE vivid/ubuntu-core_jasypt: DNE xenial_jasypt: ignored (end of standard support, was needed) yakkety_jasypt: not-affected (1.9.2-1) zesty_jasypt: not-affected (1.9.2-1) artful_jasypt: not-affected (1.9.2-1) bionic_jasypt: not-affected (1.9.2-1) cosmic_jasypt: not-affected (1.9.2-1) disco_jasypt: not-affected (1.9.2-1) eoan_jasypt: not-affected (1.9.2-1) focal_jasypt: not-affected (1.9.2-1) groovy_jasypt: not-affected (1.9.2-1) hirsute_jasypt: not-affected (1.9.2-1) impish_jasypt: not-affected (1.9.2-1) jammy_jasypt: not-affected (1.9.2-1) devel_jasypt: not-affected (1.9.2-1)