Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of “null”.
Users of affected versions should apply the following mitigation:
There are no other mitigation steps necessary.
This issue was identified and responsibly reported by Tim Büthe and Daniel Neagaru from mytaxi.
2019-06-19: Initial vulnerability report published
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy