CVE-2019-11272
published 2019-06-26CVE-2019-11272: Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application…
PriorityP342high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
1.37%
68.9th percentile
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of "null".
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| spring | spring_security | >= 4.2 < 4.2.13.RELEASE | 4.2.13.RELEASE |
| vmware | spring_security | < 4.2.13 | 4.2.13 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Insufficiently Protected Credentials and Improper Authentication in Spring Security
osv·2019-06-27
CVE-2019-11272 [HIGH] Insufficiently Protected Credentials and Improper Authentication in Spring Security
Insufficiently Protected Credentials and Improper Authentication in Spring Security
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of ?null?.
GHSA
Insufficiently Protected Credentials and Improper Authentication in Spring Security
ghsa·2019-06-27
CVE-2019-11272 [HIGH] CWE-287 Insufficiently Protected Credentials and Improper Authentication in Spring Security
Insufficiently Protected Credentials and Improper Authentication in Spring Security
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of ?null?.
Red Hat
spring-security-core: mishandling of user passwords allows logging in with a password of NULL
vendor_redhat·2019-07-11·CVSS 7.3
CVE-2019-11272 [HIGH] CWE-305 spring-security-core: mishandling of user passwords allows logging in with a password of NULL
spring-security-core: mishandling of user passwords allows logging in with a password of NULL
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of "null".
A flaw was found in Spring Security in several versions, in the use of plain text passwords using the PlaintextPasswordEncoder. If an application is using an affected version of Spring Security with the PlaintextPasswordEncoder and a user has a null encoded password, an attacker can use this flaw to authenticate using a password of "null."
State
No detection rules found.
No public exploits indexed.
2019-06-26
Published