01642 06 11 11 Arrange Call

Authentication Bypass Vulnerability in Spring Security

CVE-2014-0097 · HIGH

CVE-2014-0097

The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.

Learn more about our Cis Benchmark Audit For Bind.