CVE-2014-0097
Description
The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.
CWE
- (none)
Affected
- Pivotal / Spring Security — v=3.2.0 to 3.2.1 [affected]; v=3.1.0 to 3.1.5 [affected]
CVSS
- (none)
References
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISC
- https://pivotal.io/security/cve-2014-0097 x_refsource_CONFIRM
Source
cvelistV5-main/cves/2014/0xxx/CVE-2014-0097.json