CVE-2017-8028
libspring-ldap-java - security update
8.1
HIGH
CVSS 3.1
EPSS 2.6%
Description
In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as the authentication strategy, and setting userSearch, authentication is allowed with an arbitrary password when the username is correct. This occurs because some LDAP vendors require an explicit operation for the LDAP bind to take effect.
How to fix CVE-2017-8028
To remediate CVE-2017-8028, upgrade the affected package to a fixed version below.
- —upgrade to 1.3.1.RELEASE-4+deb7u1 or later
- —upgrade to 1.3.1.RELEASE-5+deb8u1 or later
- —upgrade to 2.3.2 or later
Is CVE-2017-8028 being exploited?
Low — EPSS is 2.6%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 1.3.1.RELEASE-4+deb7u1
- from 0, < 1.3.1.RELEASE-5+deb8u1
- >= 1.3.0, < 2.3.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |