Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreWhen connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as the authentication strategy, and setting userSearch, authentication is allowed with an arbitrary password when the username is correct. This occurs because some LDAP vendors require an explicit operation for the LDAP bind to take effect.
Users of affected versions should apply the following mitigation:
This vulnerability was responsibly reported by Tobias Schneider.
2017-10-16: Initial vulnerability report published
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy