CVE-2014-0097
CVE-2014-0097
The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.
Productos afectados
Pivotal · Spring Security¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →