bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password. CREATE(Triage):(User=admin) CVE-2017-7252 (https://nvd.nist.gov/vuln/detail/CVE-2017-7252)