- EPSS 0.98%
- Veröffentlicht 23.02.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:49:31
Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause th...
CVE-2020-5408
- EPSS 0.41%
- Veröffentlicht 14.05.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:06
Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A ...
CVE-2019-11272
- EPSS 0.41%
- Veröffentlicht 26.06.2019 14:15:09
- Zuletzt bearbeitet 12.09.2025 19:44:04
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user...
CVE-2019-3795
- EPSS 0.55%
- Veröffentlicht 09.04.2019 16:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:33
Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an ...
CVE-2018-1199
- EPSS 0.85%
- Veröffentlicht 16.03.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:22
Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a ...
CVE-2017-4995
- EPSS 0.83%
- Veröffentlicht 27.11.2017 10:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An issue was discovered in Pivotal Spring Security 4.2.0.RELEASE through 4.2.2.RELEASE, and Spring Security 5.0.0.M1. When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execut...
CVE-2016-5007
- EPSS 0.16%
- Veröffentlicht 25.05.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Differences in the strictness of the pattern matching me...
CVE-2014-3527
- EPSS 0.36%
- Veröffentlicht 25.05.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact that the proxy ticket authent...
CVE-2014-0097
- EPSS 0.23%
- Veröffentlicht 25.05.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.
CVE-2016-9879
- EPSS 0.32%
- Veröffentlicht 06.01.2017 22:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL path parameter with an encoded "...