QID 982339

QID 982339: Java (maven) Security Update for org.springframework.security:spring-security-core (GHSA-v33x-prhc-gph5)

Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of ?null?.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-v33x-prhc-gph5 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982339

    Software Advisories
    Advisory ID Software Component Link
    GHSA-v33x-prhc-gph5 org.springframework.security:spring-security-core URL Logo github.com/advisories/GHSA-v33x-prhc-gph5