CVE-2014-0097
Description
The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.
Risk Information
Base Score
7.3
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
Exploitation Probability
0.314
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2014-0097 are fixed in Spring-security-core 3.2.2 | Windows |
| Vulnerabilities CVE-2014-0097 are fixed in Spring-security-core 3.1.5 | Windows |
| Vulnerabilities CVE-2014-0097 are fixed in Spring-security-core for Linux 3.2.2 | Linux |
| Vulnerabilities CVE-2014-0097 are fixed in Spring-security-core for Linux 3.1.5 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234