The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.springframework.security:spring-security-core(Maven) | 3.2.0 | 3.2.2.RELEASE | N/A |
| org.springframework.security:spring-security-core(Maven) | 3.1.0 | 3.1.5.RELEASE | N/A |
CVSS Metrics