Usage of weak hashing library on a password (SHA-1)
Overview
Rule ID:
javascript_lang_weak_password_hash_sha1
Applicable Languages: Javascript
Weakness ID: CWE-326
Description
Using weak hashing algorithms like SHA-1 for password storage undermines security. These algorithms are prone to attacks, making it easier for attackers to crack passwords and access sensitive information.
Remediation Guidelines
Avoid using SHA-1 for hashing passwords, as it is no longer deemed secure due to its susceptibility to various attacks.
Use a recommended hashing library like Argon2id for hashing passwords. This method strengthens security by offering a more effective defense against brute-force attacks.
References
Configuration
To omit this rule during a scan, and to provide you with continuous 24/7 code-level scanning, you can employ our SAST TOOL
Last updated