Release date:
Updated on:
Affected Systems:
SpringSource Spring Security 3.2.0-3.2.1
SpringSource Spring Security 3.1.0-3.1.5
SpringSource Spring Security
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66135
CVE (CAN) ID: CVE-2014-0097
The predecessor of Spring Security is Acegi Security, which is the framework used by the Spring Project Team to provide Security authentication services.
The ActiveDirectoryLdapAuthenticator of Spring Security does not check the password length. If the Directory allows anonymous binding, the user identity may be incorrectly verified.
<* Source: Spring Development team
Link: http://www.securityfocus.com/archive/1/531424
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SpringSource
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://support.springsource.com/security/
Http://www.gopivotal.com/security/cve-2014-0097
Https://jira.springsource.org/browse/SEC-2500
Https://github.com/spring-projects/spring-security/commit/88559882e96708
5c47a7e1dcbc4dc32c2c796868
Https://github.com/spring-projects/spring-security/commit/7dbb8e777ece86
75f3333a1ef1cb4d6b9be80395
Https://github.com/spring-projects/spring-security/commit/a7005bd74241ac
8e2e7b38ae31bc4b0f641ef973