In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.
The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
Link | Tags |
---|---|
https://blog.jetbrains.com/blog/2021/08/05/jetbrains-security-bulletin-q2-2021/ | vendor advisory |