Menu

#742 Veracode reports issue on jtds-1.3.1.jar

v1.3
wont-fix
momo
None
1
2015-03-06
2015-02-23
No

Hi, Am using jtds-1.3.1.jar in one of my component. When I submitted the jtds-1.3.1.jar for veracode scan, Veracode reported a Sev 5 defect saying "Use of a Broken or Risky Cryptographic Algorithm" on MD5Digest.java line number 41.

Could you please visit this and let me know if there is a future version that has this defect addressed? Thanks in Advance....

Discussion

  • momo

    momo - 2015-03-06
    • status: open --> wont-fix
    • assigned_to: momo
     
  • momo

    momo - 2015-03-06

    This isn't a defect at all. MD5 hashes are required for NTLM authentication.

    Cheers,
    momo

     

Log in to post a comment.

MongoDB Logo MongoDB