PT-2017-4053 · Pivotal · Spring Ldap

Publicado

2017-11-22

·

Atualizado

2022-05-13

·

CVE-2017-8028

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pivotal Spring-LDAP versions 1.3.0 through 2.3.1
Description The issue is related to authentication errors in the LDAP module of the Spring Security Java framework. When connected to certain LDAP servers and using the LDAP BindAuthenticator with the org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as the authentication strategy, authentication is allowed with an arbitrary password if the username is correct. This occurs because some LDAP vendors require an explicit operation for the LDAP bind to take effect.
Recommendations For Pivotal Spring-LDAP versions 1.3.0 through 2.3.1, consider updating the authentication strategy to prevent authentication with arbitrary passwords. As a temporary workaround, restrict access to the LDAP BindAuthenticator until a patch is available. Additionally, review the configuration of the userSearch and authentication settings to ensure they are properly secured. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2021-01068
CVE-2017-8028
DLA-1180-1
DSA-4046-1
GHSA-PJQH-2JCC-5J84
MGASA-2018-0235

Produtos afetados

Spring Ldap