Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious user with access to the data that has been encrypted using such an encryptor may be able to derive the unencrypted values using a dictionary attack.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NPivotal Software Spring Security
APPPivotal Software5.2.0 – 5.2.4 (bez)5.3.0 – 5.3.2 (bez)VMware Spring Security
APPVmware4.2.0 – 4.2.16 (bez)5.0.0 – 5.0.16 (bez)5.1.0 – 5.1.10 (bez)
Powiązane podatności
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrat...
In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client R...
VMware Spring Security — brak zapisu nagłówków HTTP odpowiedzi
Spring Security WebFlux: ominięcie zabezpieczeń przez wzorzec "**"
Spring Security: pominięcie reguł autoryzacji przez forward/include dispatcher