Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2019-11272

около 7 лет назад

Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of "null".

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2019-11272

около 7 лет назад

Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of "null".

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2019-11272

около 7 лет назад

Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of "null".

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2019-11272

около 7 лет назад

Spring Security, versions 4.2.x up to 4.2.12, and older unsupported ve ...

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-v33x-prhc-gph5

около 7 лет назад

Insufficiently Protected Credentials and Improper Authentication in Spring Security

CVSS3: 7.3
EPSS: Низкий
fstec логотип

BDU:2019-02938

около 7 лет назад

Уязвимость реализации класса PlaintextPasswordEncoder Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-11272

Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of "null".

CVSS3: 7.3
1%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-11272

Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of "null".

CVSS3: 7.3
1%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-11272

Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of "null".

CVSS3: 7.3
1%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11272

Spring Security, versions 4.2.x up to 4.2.12, and older unsupported ve ...

CVSS3: 7.3
1%
Низкий
около 7 лет назад
github логотип
GHSA-v33x-prhc-gph5

Insufficiently Protected Credentials and Improper Authentication in Spring Security

CVSS3: 7.3
1%
Низкий
около 7 лет назад
fstec логотип
BDU:2019-02938

Уязвимость реализации класса PlaintextPasswordEncoder Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.3
1%
Низкий
около 7 лет назад

Уязвимостей на страницу