ZeroHour

CVE-2019-11272

CVSS 3.1
7.3 high
EPSS
1%p71
Published
()
Modified
Description

Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of "null".

Vendors
vmwaredebian
Products
spring security, debian linux
Weakness
CWE-287, CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.