Description
The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.
Affected products
- Pivotal / Spring Security3.2.0 to 3.2.1 – 3.2.0 to 3.2.1
- Pivotal / Spring Security3.1.0 to 3.1.5 – 3.1.0 to 3.1.5
References
Updated 38m ago · 8 sources