Security Advisory

CVE-2012-5055

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2012-12-05 17:00:00
Last updated 2024-09-16 23:11:00
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.