CVE-2017-8028
published 2017-11-27CVE-2017-8028: In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP…
PriorityP348high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
2.61%
83.8th percentile
In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as the authentication strategy, and setting userSearch, authentication is allowed with an arbitrary password when the username is correct. This occurs because some LDAP vendors require an explicit operation for the LDAP bind to take effect.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| pivotal_software | spring-ldap | — | — |
| pivotal_software | spring-ldap | — | — |
| pivotal_software | spring-ldap | — | — |
| pivotal_software | spring-ldap | — | — |
| pivotal_software | spring-ldap | — | — |
| pivotal_software | spring-ldap | — | — |
| pivotal_software | spring-ldap | — | — |
| pivotal_software | spring-ldap | — | — |
| pivotal_software | spring-ldap | — | — |
| pivotal_software | spring-ldap | — | — |
| pivotal_software | spring-ldap | — | — |
| pivotal_software | spring-ldap | — | — |
| pivotal_software | spring-ldap | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_oracle8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Retail Applications Risk Matrix: Posting (Spring-LDAP) — CVE-2017-8028
vendor_oracle·2021-01-15·CVSS 8.1
CVE-2017-8028 [HIGH] Oracle Oracle Retail Applications Risk Matrix: Posting (Spring-LDAP) — CVE-2017-8028
Oracle Oracle Retail Applications Risk Matrix: Posting (Spring-LDAP) vulnerability
CVE: CVE-2017-8028
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Red Hat
spring-ldap: Authentication with userSearch and STARTTLS allows authentication with arbitrary password
vendor_redhat·2017-10-16·CVSS 8.1
CVE-2017-8028 [HIGH] CWE-287 spring-ldap: Authentication with userSearch and STARTTLS allows authentication with arbitrary password
spring-ldap: Authentication with userSearch and STARTTLS allows authentication with arbitrary password
In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as the authentication strategy, and setting userSearch, authentication is allowed with an arbitrary password when the username is correct. This occurs because some LDAP vendors require an explicit operation for the LDAP bind to take effect.
A vulnerability was found in spring-ldap that allows an attacker to authenticate with an arbitrary password. When spring-ldap connected to some LDAP servers, when no additional attributes are bound, when u
OSV
Improper Authentication in Pivotal Spring-LDAP
osv·2022-05-13
CVE-2017-8028 [HIGH] Improper Authentication in Pivotal Spring-LDAP
Improper Authentication in Pivotal Spring-LDAP
In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as the authentication strategy, and setting userSearch, authentication is allowed with an arbitrary password when the username is correct. This occurs because some LDAP vendors require an explicit operation for the LDAP bind to take effect.
GHSA
Improper Authentication in Pivotal Spring-LDAP
ghsa·2022-05-13
CVE-2017-8028 [HIGH] CWE-287 Improper Authentication in Pivotal Spring-LDAP
Improper Authentication in Pivotal Spring-LDAP
In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as the authentication strategy, and setting userSearch, authentication is allowed with an arbitrary password when the username is correct. This occurs because some LDAP vendors require an explicit operation for the LDAP bind to take effect.
OSV
CVE-2017-8028: In Pivotal Spring-LDAP versions 1
osv·2017-11-27·CVSS 8.1
CVE-2017-8028 [HIGH] CVE-2017-8028: In Pivotal Spring-LDAP versions 1
In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as the authentication strategy, and setting userSearch, authentication is allowed with an arbitrary password when the username is correct. This occurs because some LDAP vendors require an explicit operation for the LDAP bind to take effect.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-8028 spring-ldap: Authentication with userSearch and STARTTLS allows authentication with arbitrary password
bugzilla·2017-11-08·CVSS 8.1
CVE-2017-8028 [HIGH] CVE-2017-8028 spring-ldap: Authentication with userSearch and STARTTLS allows authentication with arbitrary password
CVE-2017-8028 spring-ldap: Authentication with userSearch and STARTTLS allows authentication with arbitrary password
When connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as the authentication strategy, and setting userSearch, authentication is allowed with an arbitrary password when the username is correct. This occurs because some LDAP vendors require an explicit operation for the LDAP bind to take effect.
References:
https://pivotal.io/security/cve-2017-8028
Upstream issue:
https://github.com/spring-projects/spring-ldap/issues/430
Discussion:
Created spring-ldap tracking bugs for this issue:
Affects: fedora-all [bug 1510970]
---
An
Bugzilla
CVE-2017-8028 spring-ldap: Authentication with userSearch and STARTTLS allows authentication with arbitrary password [fedora-all]
bugzilla·2017-11-08·CVSS 8.1
CVE-2017-8028 [HIGH] CVE-2017-8028 spring-ldap: Authentication with userSearch and STARTTLS allows authentication with arbitrary password [fedora-all]
CVE-2017-8028 spring-ldap: Authentication with userSearch and STARTTLS allows authentication with arbitrary password [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
https://access.redhat.com/errata/RHSA-2018:0319https://lists.debian.org/debian-lts-announce/2017/11/msg00026.htmlhttps://pivotal.io/security/cve-2017-8028https://www.debian.org/security/2017/dsa-4046https://www.oracle.com/security-alerts/cpujan2021.htmlhttps://access.redhat.com/errata/RHSA-2018:0319https://lists.debian.org/debian-lts-announce/2017/11/msg00026.htmlhttps://pivotal.io/security/cve-2017-8028https://www.debian.org/security/2017/dsa-4046https://www.oracle.com/security-alerts/cpujan2021.html
2017-11-27
Published