Bug 1075302 (CVE-2014-0097) - CVE-2014-0097 Spring Framework: empty passwords may bypass authentication
Summary: CVE-2014-0097 Spring Framework: empty passwords may bypass authentication
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2014-0097
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1075303
Blocks: 1075304
TreeView+ depends on / blocked
 
Reported: 2014-03-12 03:38 UTC by Murray McAllister
Modified: 2021-02-17 06:47 UTC (History)
6 users (show)

Fixed In Version: spring security 3.2.2
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2014-03-17 20:57:56 UTC
Embargoed:


Attachments (Terms of Use)

Description Murray McAllister 2014-03-12 03:38:40 UTC
It was found that empty passwords could bypass authentication. From the original advisory:

"The ActiveDirectoryLdapAuthenticator does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password."

This issue affects versions 3.2.0 to 3.2.1, and versions 3.1.0 to 3.1.5.

External References:

http://www.gopivotal.com/security/cve-2014-0097

Comment 1 Murray McAllister 2014-03-12 03:40:52 UTC
Created springframework-security tracking bugs for this issue:

Affects: fedora-all [bug 1075303]

Comment 2 Chess Hazlett 2014-03-17 20:57:56 UTC
Statement:

Not Vulnerable. This issue does not affect Spring as shipped with various Red Hat products.


Note You need to log in before you can comment on or make changes to this bug.