Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gv9v-c375-hvmg

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

Improper Authentication in Spring Security

The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.

Пакеты

Наименование

org.springframework.security:spring-security-core

maven
Затронутые версииВерсия исправления

>= 3.2.0, <= 3.2.1.RELEASE

3.2.2.RELEASE

Наименование

org.springframework.security:spring-security-core

maven
Затронутые версииВерсия исправления

>= 3.1.0, <= 3.1.4.RELEASE

3.1.5.RELEASE

EPSS

Процентиль: 54%
0.00314
Низкий

7.3 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.3
ubuntu
больше 8 лет назад

The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.

redhat
почти 12 лет назад

The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.

CVSS3: 7.3
nvd
больше 8 лет назад

The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.

CVSS3: 7.3
debian
больше 8 лет назад

The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 ...

EPSS

Процентиль: 54%
0.00314
Низкий

7.3 High

CVSS3

Дефекты

CWE-287