Blowfish should use a large key

This page is not yet available in Spanish. We are working on its translation.
If you have any questions or feedback about our current translation project, feel free to reach out to us!

Metadata

ID: java-security/blowfish-short-key

Language: Java

Severity: Warning

Category: Security

CWE: 326

Description

When using Blowfish, use at least 128 bits of entropy to prevent potential vulnerabilities.

Learn More

Arguments

  • min-length: Minimum length for a Blowfish key. Default: 128.

Non-Compliant Code Examples

public class MyClass {

    public void test () {
        KeyGenerator keyGen = KeyGenerator.getInstance("Blowfish");
        keyGen.init(64);
    }
}

Compliant Code Examples

public class MyClass {

    public void test () {
        KeyGenerator keyGen = KeyGenerator.getInstance("Blowfish");
        keyGen.init(128);
    }
}
https://static.datadoghq.com/static/images/logos/github_avatar.svg https://static.datadoghq.com/static/images/logos/vscode_avatar.svg jetbrains

Seamless integrations. Try Datadog Code Analysis