Beveiligingsadvies

CVE-2014-0097

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2017-05-25 17:00:00
Laatst bijgewerkt 2024-08-06 09:05:38
Toegewezen door dell
CVSS-score geen score
Status PUBLISHED

Beschrijving

The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.