Uploaded image for project: 'Groovy'
  1. Groovy
  2. GROOVY-11459

weak hashing algorithm (使用弱哈希算法)

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 4.0.22
    • 5.0.0-alpha-11, 4.0.24
    • None
    • None

    Description

      通过iast扫描发现groovy中使用了md5来生成缓存键名,路径为groovy.lang.GroovyClassLoader.getSourceCacheKey

      建议使用常见的安全的哈希算法,如SHA-256,SHA-384,SHA-512等

      Google Translate gives:
      Through iast scanning, it was found that md5 is used in groovy to generate the cache key name, and the path is groovy.lang.GroovyClassLoader.getSourceCacheKey

      It is recommended to use common secure hash algorithms, such as SHA-256, SHA-384, SHA-512, etc.

      Attachments

        Issue Links

          Activity

            People

              paulk Paul King
              wellchang wellchang
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: