From 5f658b3ffcfb748528e760df35aa80fb85027981 Mon Sep 17 00:00:00 2001 From: vitaliy_kuzmich Date: Thu, 16 Jun 2016 14:48:54 +0300 Subject: [PATCH] Remove double salt in Pbkdf2PasswordEncoder Issue gh-3930 --- .../security/crypto/password/Pbkdf2PasswordEncoder.java | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/crypto/src/main/java/org/springframework/security/crypto/password/Pbkdf2PasswordEncoder.java b/crypto/src/main/java/org/springframework/security/crypto/password/Pbkdf2PasswordEncoder.java index c74b70c23d..58b2631cb5 100644 --- a/crypto/src/main/java/org/springframework/security/crypto/password/Pbkdf2PasswordEncoder.java +++ b/crypto/src/main/java/org/springframework/security/crypto/password/Pbkdf2PasswordEncoder.java @@ -101,7 +101,7 @@ public class Pbkdf2PasswordEncoder implements PasswordEncoder { } private byte[] encodeAndConcatenate(CharSequence rawPassword, byte[] salt) { - return concatenate(salt, encode(rawPassword, salt)); + return encode(rawPassword, salt); } /** @@ -130,4 +130,4 @@ public class Pbkdf2PasswordEncoder implements PasswordEncoder { throw new IllegalStateException("Could not create hash", e); } } -} \ No newline at end of file +}