← Back to CVE List

CVE-2014-0097

Published: 2017-05-25T17:29Z
Last Modified: 2024-11-21T02:01Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt