jasypt before 1.9.2 allows a timing attack against the password hash comparison.
{ "urgency": "not yet assigned" }