CVE-2012-5055
published 2012-12-05CVE-2012-5055: DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the…
PriorityP426medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.94%
77.7th percentile
DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | springsource_spring_security | <= 2.0.6 | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
| vmware | springsource_spring_security | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Security: Ability to determine if username is valid via DaoAuthenticationProvider
vendor_redhat·2012-10-09·CVSS 5.0
CVE-2012-5055 [MEDIUM] Security: Ability to determine if username is valid via DaoAuthenticationProvider
Security: Ability to determine if username is valid via DaoAuthenticationProvider
DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Spring Security
ghsa·2022-05-17
CVE-2012-5055 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Spring Security
Exposure of Sensitive Information to an Unauthorized Actor in Spring Security
DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Spring Security
osv·2022-05-17
CVE-2012-5055 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor in Spring Security
Exposure of Sensitive Information to an Unauthorized Actor in Spring Security
DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.
No detection rules found.
No public exploits indexed.
2012-12-05
Published