The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.
2017-05-25T17:29:00.160
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.3 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | spring_security | 3.1.0 | Yes |
Application | vmware | spring_security | 3.1.1 | Yes |
Application | vmware | spring_security | 3.1.2 | Yes |
Application | vmware | spring_security | 3.1.3 | Yes |
Application | vmware | spring_security | 3.1.4 | Yes |
Application | vmware | spring_security | 3.1.5 | Yes |
Application | vmware | spring_security | 3.2.0 | Yes |
Application | vmware | spring_security | 3.2.1 | Yes |