Executive brief
jasypt-spring-boot is a library used to encrypt sensitive configuration data (like database passwords) in Spring Boot applications. A security flaw exists where the library uses a predictable, all-zero 'salt' when deriving encryption keys from a master password by default. This makes it significantly easier for attackers to crack encrypted secrets using precomputed tables and results in the same encryption keys being used across different installations that share a master password.
Technical details
The vulnerability stems from insecure cryptographic defaults in `SimpleGCMConfig.java` and `StringEncryptorBuilder.java`. Specifically, `getSecretKeySaltGenerator()` defaults to `org.jasypt.salt.ZeroSaltGenerator` when no salt is explicitly configured, leading to deterministic key derivation via PBKDF2-HMAC-SHA256. Additionally, the library uses a default of 1,000 iterations for PBKDF2, which is significantly below modern security recommendations. An attacker with access to encrypted configuration ciphertexts could perform offline brute-force attacks more efficiently using rainbow tables, as the predictable salt eliminates the per-target cost of key derivation. As of the advisory date, no official patch has been released, and users are advised to manually configure unique salts and higher iteration counts.
Affected products
- ulisesbocchio jasypt-spring-boot 3.0.0 - 4.0.4
- ulisesbocchio jasypt-spring-boot-starter 3.0.0 - 4.0.4
Timeline
- 2026-05-24: disclosed: Vulnerability reported via GitHub issues and NVD
- 2026-05-26: advisory: GitHub Advisory published