Pivotal Spring Security是美国Pivotal Software公司的一套为基于Spring的应用程序提供说明性安全保护的安全框架。 Pivotal Spring Security中的ActiveDirectoryLdapAuthenticator存在安全漏洞,该漏洞源于程序没有检测密码长度。攻击者可借助空密码利用该漏洞绕过用户身份验证。以下版本受到影响:Spring Security 3.2.0版本至3.2.1版本,3.1.0版本至3.1.5版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Pivotal | Spring Security | 3.2.0 to 3.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2014-0225 | Pivotal Spring Framework 安全漏洞 | |
| CVE-2014-3527 | Pivotal Spring Security 安全漏洞 | |
| CVE-2015-1834 | Pivotal Cloud Foundry Elastic Runtime和cf-release 路径遍历漏洞 | |
| CVE-2015-3189 | 多款Pivotal产品安全漏洞 | |
| CVE-2015-3190 | 多款Pivotal产品安全漏洞 | |
| CVE-2015-3191 | 多款Pivotal产品安全漏洞 | |
| CVE-2016-0761 | Pivotal Cloud Foundry Garden-Linux和Elastic Runtime 安全漏洞 | |
| CVE-2016-0780 | Pivotal Cloud Foundry Elastic Runtime和cf-release 安全漏洞 | |
| CVE-2016-0781 | 多款Pivotal产品安全漏洞 | |
| CVE-2016-2165 | Pivotal Elastic Runtime和cf-release 安全漏洞 | |
| CVE-2016-3084 | 多款Pivotal产品安全漏洞 | |
| CVE-2016-4435 | BOSH Director VM 安全漏洞 | |
| CVE-2016-4977 | Pivotal Spring Security OAuth 安全漏洞 | |
| CVE-2016-5007 | Pivotal Spring Security和Spring Framework 安全漏洞 |
No comments yet