---
id: CVE-2026-107829
title: >-
  Jivejdon through 5.0 contains a weak password storage vulnerability that
  stores account passwords as unsalted MD5 digests via ToolsUtil.hash() in
  AccountDaoSql
summary: >-
  Jivejdon through 5.0 contains a weak password storage vulnerability that
  stores account passwords as unsalted MD5 digests via ToolsUtil.hash() in
  AccountDaoSql. Attackers who obtain the user table through database access or
  SQL injection…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-916
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:30.640'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107829'
references:
  - url: 'https://github.com/banq/jivejdon'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/auth/jaas/DigestUtil.java#L30-L44
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/auth/jaas/JiveJdonLoginMoudle.java#L86
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/infrastructure/repository/dao/sql/AccountDaoSql.java#L181
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/infrastructure/repository/dao/sql/AccountDaoSql.java#L253
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/util/ToolsUtil.java#L198-L211
    label: disclosure@vulncheck.com
  - url: 'https://github.com/banq/jivejdon/issues/28'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/jivejdon-through-5.0-unsalted-md5-password-storage-via-accountdaosql
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-08T23:16:47.393Z'
---

## Overview

Jivejdon through 5.0 contains a weak password storage vulnerability that stores account passwords as unsalted MD5 digests via ToolsUtil.hash() in AccountDaoSql. Attackers who obtain the user table through database access or SQL injection can crack passwords with precomputed tables or GPU attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
