insecure-crypto-algorithm-blowfish
The use of the insecure Blowfish encryption algorithm was detected. Blowfish uses a 64-bit block size that makes it vulnerable to birthday attacks, and is therefore considered unfit for purpose.
Likelihood: MEDIUM
Confidence: HIGH
CWE:
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm
OWASP:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures
insecure-crypto-algorithm-blowfish
The use of the insecure Blowfish encryption algorithm was detected. Blowfish uses a 64-bit block size that makes it vulnerable to birthday attacks, and is therefore considered unfit for purpose.
Likelihood: MEDIUM
Confidence: HIGH
CWE:
- CWE-327: Use of a Broken or Risky Cryptographic Algorithm
OWASP:
- A03:2017 - Sensitive Data Exposure
- A02:2021 - Cryptographic Failures