Spring ActiveDirectoryLdapAuthenticator身份验证绕过漏洞


发布日期:2014-03-12
更新日期:2014-03-17

受影响系统:
SpringSource Spring Security 3.2.0 - 3.2.1
SpringSource Spring Security 3.1.0 - 3.1.5
SpringSource Spring Security
描述:
--------------------------------------------------------------------------------
BUGTRAQ  ID: 66135
CVE(CAN) ID: CVE-2014-0097

Spring Security的前身是Acegi Security,是Spring项目组中用来提供安全认证服务的框架。

Spring Security的ActiveDirectoryLdapAuthenticator没有检查密码长度。如果目录允许匿名绑定,则可能会错误的验证用户身份。

<*来源:Spring Development team
 
  链接:http://www.securityfocus.com/archive/1/531424
*>

建议:
--------------------------------------------------------------------------------
厂商补丁:

SpringSource
------------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

http://support.springsource.com/security/

http://www.gopivotal.com/security/cve-2014-0097
https://jira.springsource.org/browse/SEC-2500
https://github.com/spring-projects/spring-security/commit/88559882e96708
5c47a7e1dcbc4dc32c2c796868
https://github.com/spring-projects/spring-security/commit/7dbb8e777ece86
75f3333a1ef1cb4d6b9be80395
https://github.com/spring-projects/spring-security/commit/a7005bd74241ac
8e2e7b38ae31bc4b0f641ef973

相关内容