← volver
CVE-2014-0097

CVE-2014-0097

EPSS 1.2%
The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.
Productos afectados
Pivotal · Spring Security

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →