logo

Identifying and Remediating CWE-328 Reversible One-Way Hash in Django Applications

ID: e7940927-7944-535a-b13a-edf7f236a54f

STIX ID: report--e7940927-7944-535a-b13a-edf7f236a54f

Feed Name: HackerOne Blog

Threat Score
25/100

Date Published: 2024-01-24

Date Updated: 2026-06-12

...
...

This report explains CWE-328 (reversible one-way hash) in the context of Django, demonstrates a vulnerable MD5-based password hashing example, identifies common causes like weak algorithms and improper salting, and recommends remediation such as using Django's built-in PBKDF2/bcrypt hashers, secure salting, and avoiding custom hash functions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.