← back
CVE-2014-0097

CVE-2014-0097

EPSS 1.2%
The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →