{"id":"CVE-2014-0097","aliases":[],"url":"https://o3.security/vulnerability/CVE-2014-0097","summary":"Improper Authentication in Spring Security","details":"The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.","published":"2022-05-13T01:01:04Z","modified":"2023-11-08T03:57:31.262737Z","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.springframework.security:spring-security-core","fixedVersion":"3.2.2.RELEASE"},{"ecosystem":"Maven","name":"org.springframework.security:spring-security-core","fixedVersion":"3.1.5.RELEASE"}],"fix":{"url":"https://github.com/spring-projects/spring-security/commit/7dbb8e777ece8675f3333a1ef1cb4d6b9be80395","label":"spring-projects/spring-security@7dbb8e7"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0097"},{"type":"WEB","url":"https://github.com/spring-projects/spring-security/commit/7dbb8e777ece8675f3333a1ef1cb4d6b9be80395"},{"type":"WEB","url":"https://github.com/spring-projects/spring-security/commit/88559882e967085c47a7e1dcbc4dc32c2c796868"},{"type":"WEB","url":"https://github.com/spring-projects/spring-security/commit/a7005bd74241ac8e2e7b38ae31bc4b0f641ef973"},{"type":"WEB","url":"https://jira.springsource.org/browse/SEC-2500"},{"type":"WEB","url":"https://pivotal.io/security/cve-2014-0097"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:57:31.262737Z"}}