Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0097

Опубликовано: 25 мая 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 7.3

Описание

The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

not-affected

lucid

DNE

precise

not-affected

saucy

not-affected

trusty

not-affected

trusty/esm

not-affected

upstream

released

3.1.6, 3.2.2

Показывать по

EPSS

Процентиль: 54%
0.00314
Низкий

7.5 High

CVSS2

7.3 High

CVSS3

Связанные уязвимости

redhat
почти 12 лет назад

The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.

CVSS3: 7.3
nvd
больше 8 лет назад

The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.

CVSS3: 7.3
debian
больше 8 лет назад

The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 ...

CVSS3: 7.3
github
больше 3 лет назад

Improper Authentication in Spring Security

EPSS

Процентиль: 54%
0.00314
Низкий

7.5 High

CVSS2

7.3 High

CVSS3