{"id":"GHSA-gv9v-c375-hvmg","summary":"Improper Authentication in Spring Security","details":"The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.","aliases":["CVE-2014-0097"],"modified":"2023-11-08T03:57:31.262737Z","published":"2022-05-13T01:01:04Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-07-07T23:04:22Z","nvd_published_at":"2017-05-25T17:29:00Z","cwe_ids":["CWE-287"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0097"},{"type":"WEB","url":"https://github.com/spring-projects/spring-security/commit/7dbb8e777ece8675f3333a1ef1cb4d6b9be80395"},{"type":"WEB","url":"https://github.com/spring-projects/spring-security/commit/88559882e967085c47a7e1dcbc4dc32c2c796868"},{"type":"WEB","url":"https://github.com/spring-projects/spring-security/commit/a7005bd74241ac8e2e7b38ae31bc4b0f641ef973"},{"type":"WEB","url":"https://jira.springsource.org/browse/SEC-2500"},{"type":"WEB","url":"https://pivotal.io/security/cve-2014-0097"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"}],"affected":[{"package":{"name":"org.springframework.security:spring-security-core","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security/spring-security-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.2.0"},{"fixed":"3.2.2.RELEASE"}]}],"versions":["3.2.0.RELEASE","3.2.1.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gv9v-c375-hvmg/GHSA-gv9v-c375-hvmg.json","last_known_affected_version_range":"\u003c= 3.2.1.RELEASE"}},{"package":{"name":"org.springframework.security:spring-security-core","ecosystem":"Maven","purl":"pkg:maven/org.springframework.security/spring-security-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.1.0"},{"fixed":"3.1.5.RELEASE"}]}],"versions":["3.1.0.RELEASE","3.1.1.RELEASE","3.1.2.RELEASE","3.1.3.RELEASE","3.1.4.RELEASE"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.1.4.RELEASE","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gv9v-c375-hvmg/GHSA-gv9v-c375-hvmg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}