wellchang created GROOVY-11459:
----------------------------------

             Summary: 使用弱哈希算法
                 Key: GROOVY-11459
                 URL: https://issues.apache.org/jira/browse/GROOVY-11459
             Project: Groovy
          Issue Type: Wish
    Affects Versions: 4.0.22
            Reporter: wellchang


通过iast扫描发现groovy中使用了md5来生成缓存键名,路径为groovy.lang.GroovyClassLoader.getSourceCacheKey

建议使用常见的安全的哈希算法,如SHA-256,SHA-384,SHA-512等



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to