漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
User Attribute Enumeration when Using DaoAuthenticationProvider
Vulnerability Description
Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's timing attack defense can be bypassed for users who are disabled, expired, or locked.This issue affects Spring Security: from 5.7.0 through 5.7.22, from 5.8.0 through 5.8.24, from 6.3.0 through 6.3.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
N/A
Vulnerability Title
Spring Security 安全漏洞
Vulnerability Description
Spring Security是Spring开源的一款具有认证和授权功能的安全框架。 Spring Security 5.7.22及之前版本、5.8.24及之前版本、6.3.15及之前版本、6.5.9及之前版本和7.0.4及之前版本存在安全漏洞,该漏洞源于使用UserDetails#isEnabled、#isAccountNonExpired或#isAccountNonLocked用户属性时,DaoAuthenticationProvider的时间攻击防御可能被禁用、过期或锁定用户绕过。
CVSS Information
N/A
Vulnerability Type
N/A