bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Feb 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published: 2023-11-03T00:00:00.000Z
Updated: 2024-09-12T19:35:01.437Z
Reserved: 2017-03-24T00:00:00.000Z
Link: CVE-2017-7252
Updated: 2024-08-05T15:56:36.359Z
Status : Modified
Published: 2023-11-03T01:15:07.777
Modified: 2024-11-21T03:31:28.793
Link: CVE-2017-7252
No data.