cbcvebase.
CVE-2017-8028
published 2017-11-27

CVE-2017-8028: In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP…

PriorityP348high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
2.61%
83.8th percentile
In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as the authentication strategy, and setting userSearch, authentication is allowed with an arbitrary password when the username is correct. This occurs because some LDAP vendors require an explicit operation for the LDAP bind to take effect.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
pivotal_softwarespring-ldap
pivotal_softwarespring-ldap
pivotal_softwarespring-ldap
pivotal_softwarespring-ldap
pivotal_softwarespring-ldap
pivotal_softwarespring-ldap
pivotal_softwarespring-ldap
pivotal_softwarespring-ldap
pivotal_softwarespring-ldap
pivotal_softwarespring-ldap
pivotal_softwarespring-ldap
pivotal_softwarespring-ldap
pivotal_softwarespring-ldap

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_oracle8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.