CVE-2025-22234: fallo de gravedad media en Spring Security
Spring Security - BCrypt Password Encoder maximum password length breaks timing attack mitigation
Publicada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.3epss 0.4%
probabilidad de explotación
0.4%top 68% de las CVE
explotación observada
noninguna fuente lo reporta
The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via response-time differences under certain configurations.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Productos afectados
Spring · Spring SecurityCVEs relacionadas — Spring Security
En el mismo producto, de las más peligrosas a las menos.
CVE-2019-3795LOWInsecure Randomness When Using a SecureRandom Instance Constructed by Spring SecurityEPSS 1.9%CVE-2019-11272—PlaintextPasswordEncoder authenticates encoded passwords that are nullEPSS 1.4%CVE-2024-22234HIGHCVE-2024-22234: Broken Access Control in Spring Security With Direct Use of isFullyAuthenticatedEPSS 0.7%CVE-2025-41232CRITICALCVE-2025-41232: Spring Security authorization bypass for method security annotations on private methodsEPSS 0.6%CVE-2025-22228HIGHCVE-2025-22228: Spring Security BCryptPasswordEncoder does not enforce maximum password lengthEPSS 0.6%CVE-2025-22223MEDIUMCVE-2025-22223EPSS 0.5%
Referencias
https://spring.io/security/cve-2025-22234/