Beveiligingsadvies

CVE-2012-5055

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2012-12-05 17:00:00
Laatst bijgewerkt 2024-09-16 23:11:00
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.