CVE-2025-22228
Vulnerability Summary
Timeline
Description
BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.
CVSS Metrics
- v3.1•HIGH•Score: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Trends
Current EPSS score: 0.59%• Percentile: 47%
Techniques & Countermeasures
- CWE-287•Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Affected Systems
- chainguard•camunda-zeebe-8.6
< 8.6.12-r1
- chainguard•camunda-zeebe-8.6-compat
< 8.6.12-r1
- chainguard•geoserver-2.27
all
- chainguard•geoserver-2.28
all
- chainguard•kayenta-2025.0
all
- chainguard•kayenta-2025.1
all
- chainguard•kayenta-2025.2
all
- chainguard•kayenta-2025.4
all
- chainguard•kayenta-2026.0
all
- chainguard•kayenta-2026.1
all
- chainguard•kayenta-fips-2025.0
all
- chainguard•kayenta-fips-2025.1
all
- chainguard•kayenta-fips-2025.2
all
- chainguard•kayenta-fips-2025.4
all
- chainguard•kayenta-fips-2026.0
all
- chainguard•kayenta-fips-2026.1
all
- chainguard•keycloak-config-cli
< 6.4.0-r3
- chainguard•keycloak-config-cli-compat
< 6.4.0-r3
- chainguard•keycloak-config-cli-iamguarded-compat
< 6.4.0-r3
- chainguard•ranger
all
- chainguard•thingsboard
< 3.9.1-r2
- chainguard•thingsboard-tb-js-executor
< 3.9.1-r2
- chainguard•thingsboard-tb-mqtt-transport
< 3.9.1-r2
- chainguard•thingsboard-tb-node
< 3.9.1-r2
- chainguard•thingsboard-tb-web-ui
< 3.9.1-r2
- wolfi•keycloak-config-cli
< 6.4.0-r3
- wolfi•keycloak-config-cli-compat
< 6.4.0-r3
- wolfi•keycloak-config-cli-iamguarded-compat
< 6.4.0-r3
- wolfi•thingsboard
< 3.9.1-r2
- wolfi•thingsboard-tb-js-executor
< 3.9.1-r2
- wolfi•thingsboard-tb-mqtt-transport
< 3.9.1-r2
- wolfi•thingsboard-tb-node
< 3.9.1-r2
- wolfi•thingsboard-tb-web-ui
< 3.9.1-r2
- org.springframework.security•spring-security-crypto
≥ 6.3.0, < 6.3.8 | ≥ 6.4.0, < 6.4.4 | ≥ 6.2.0, < 6.2.10 | ≥ 6.1.0, < 6.1.14 | ≥ 6.0.0, < 6.0.16 | ≥ 5.8.0, < 5.8.18 | < 5.7.16
- spring•spring security
≥ 5.7.x, < 5.7.16 | ≥ 5.8.x, < 5.8.18 | ≥ 6.0.x, < 6.0.16 | ≥ 6.1.x, < 6.1.14 | ≥ 6.2.x, < 6.2.10 | ≥ 6.3.x, < 6.3.8 | ≥ 6.4.x, < 6.4.4
References (6)
- https://spring.io/security/cve-2025-22228
- https://security.netapp.com/advisory/ntap-20250425-0009/
- https://nvd.nist.gov/vuln/detail/CVE-2025-22228
- https://github.com/spring-projects/spring-security/commit/46f0dc6dfc8402cd556c598fdf2d31f9d46cdbf3
- https://github.com/spring-projects/spring-security
- https://security.netapp.com/advisory/ntap-20250425-0009