http4k-security-digest is vulnerable to Use of a Broken or Risky Cryptographic Algorithm
65
Medium Risk
DigestAuthProvider.verify in the http4k Digest authentication provider ignores the configured hash algorithm. Every verification is performed with MD5 regardless of whether a stronger algorithm such as SHA-256 is configured. Deployments that believe they run SHA-256 Digest authentication silently inherit MD5's collision weaknesses and the attack paths that rely on the hash being collision-resistant. The fix hashes credentials with the configured algorithm instead of a hardcoded MD5.
You are affected if you are using a version that falls within the vulnerable range and you use http4k-security-digest for HTTP Digest authentication.
http4k-security-digest is vulnerable to Use of a Broken or Risky Cryptographic Algorithm in versions 0.0.1 - 4.50.0.0, 5.0.0.0 - 5.41.0.0 and 6.0.0.0 - 6.49.0.0.
Upgrade the org.http4k:http4k-security-digest library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant