Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-22746

Опубликовано: 22 апр. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's timing attack defense can be bypassed for users who are disabled, expired, or locked.This issue affects Spring Security: from 5.7.0 through 5.7.22, from 5.8.0 through 5.8.24, from 6.3.0 through 6.3.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.

A flaw was found in Spring Security. If an application uses the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, an attacker can bypass the DaoAuthenticationProvider's timing attack defense. This bypass allows an attacker to potentially gain limited information about disabled, expired, or locked user accounts, which could aid in further reconnaissance or attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesjenkinsFix deferred
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Fix deferred
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Fix deferred
Red Hat build of Apache Camel for Spring Boot 4spring-security-coreFix deferred
Red Hat build of Apache Camel - HawtIO 4spring-security-coreFix deferred
Red Hat build of Quarkusquarkus-spring-security-core-apiFix deferred
Red Hat Data Grid 8spring-security-coreFix deferred
Red Hat Fuse 7org.apache.servicemix.bundles.spring-security-coreFix deferred
Red Hat Fuse 7spring-security-coreFix deferred
Red Hat JBoss Enterprise Application Platform 7spring-security-coreFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-208
https://bugzilla.redhat.com/show_bug.cgi?id=2460485Spring Security: Spring Security: Timing attack defense bypass allows information disclosure

EPSS

Процентиль: 12%
0.00215
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
4 месяца назад

Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's timing attack defense can be bypassed for users who are disabled, expired, or locked.This issue affects Spring Security: from 5.7.0 through 5.7.22, from 5.8.0 through 5.8.24, from 6.3.0 through 6.3.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.

CVSS3: 3.7
nvd
4 месяца назад

Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's timing attack defense can be bypassed for users who are disabled, expired, or locked.This issue affects Spring Security: from 5.7.0 through 5.7.22, from 5.8.0 through 5.8.24, from 6.3.0 through 6.3.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.

CVSS3: 3.7
debian
4 месяца назад

Vulnerability in Spring Spring Security. If an application is using th ...

CVSS3: 3.7
github
4 месяца назад

Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider

EPSS

Процентиль: 12%
0.00215
Низкий

3.7 Low

CVSS3