← All recipes
Moderne licensed

Find weak Spring Security password encoders

Recipe IDorg.openrewrite.java.security.search.FindWeakSpringPasswordEncoder
Artifactorg.openrewrite.recipe:rewrite-java-security

Finds uses of Spring Security password encoders that are unsuitable for production password storage: NoOpPasswordEncoder (plaintext), StandardPasswordEncoder (deprecated SHA-256), MessageDigestPasswordEncoder (raw message digest), Md4PasswordEncoder (MD4, broken), LdapShaPasswordEncoder (deprecated), Md5PasswordEncoder and ShaPasswordEncoder (from the deprecated authentication.encoding package), and SCryptPasswordEncoder (deprecated in current Spring Security). Use an adaptive function such as BCryptPasswordEncoder, Argon2PasswordEncoder, or Pbkdf2PasswordEncoder instead.

Single recipesecurityCWE-327CWE-916RSPEC-S5344CWE-256Proprietary

Usage

This recipe has no required configuration options. You’ll need the Moderne CLI configured before running the command below.

mod run . --recipe org.openrewrite.java.security.search.FindWeakSpringPasswordEncoder

If the recipe isn’t available locally, install it with:

mod config recipes jar install org.openrewrite.recipe:rewrite-java-security:3.36.0

Data tables

Structured output this recipe can produce.

  • Source files that had resultsSource files that were modified by the recipe run.org.openrewrite.table.SourcesFileResults
  • Source files that had search resultsSearch results that were found during the recipe run.org.openrewrite.table.SearchResults
  • Source files that errored on a recipeThe details of all errors produced by a recipe run.org.openrewrite.table.SourcesFileErrors
  • Recipe performanceStatistics used in analyzing the performance of recipes.org.openrewrite.table.RecipeRunStats