Spring Security DaoAuthenticationProvider Username Enumeration Weakness
BID:56880
Info
Spring Security DaoAuthenticationProvider Username Enumeration Weakness
| Bugtraq ID: | 56880 |
| Class: | Design Error |
| CVE: |
CVE-2012-5055 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2012 12:00AM |
| Updated: | Mar 19 2015 08:46AM |
| Credit: | Nicholas Goodwin |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Spring Security DaoAuthenticationProvider Username Enumeration Weakness
Spring Security is prone to a username-enumeration weakness because it responds differently to login attempts depending on whether or not the username exists.
Attackers may exploit this weakness to discern valid usernames, which may aid them in brute-force password cracking or other attacks.
Spring Security is prone to a username-enumeration weakness because it responds differently to login attempts depending on whether or not the username exists.
Attackers may exploit this weakness to discern valid usernames, which may aid them in brute-force password cracking or other attacks.