发布日期:2014-03-12
更新日期:2014-03-17
受影响系统:
SpringSource Spring Security 3.2.0 - 3.2.1
SpringSource Spring Security 3.1.0 - 3.1.5
SpringSource Spring Security
描述:
--------------------------------------------------------------------------------
BUGTRAQ ID: 66135
CVE(CAN) ID: CVE-2014-0097
Spring Security的前身是Acegi Security,是Spring项目组中用来提供安全认证服务的框架。
Spring Security的ActiveDirectoryLdapAuthenticator没有检查密码长度。如果目录允许匿名绑定,则可能会错误的验证用户身份。
<*来源:Spring Development team
链接:
*>
建议:
--------------------------------------------------------------------------------
厂商补丁:
SpringSource
------------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
https://jira.springsource.org/browse/SEC-2500
https://github.com/spring-projects/spring-security/commit/88559882e96708
5c47a7e1dcbc4dc32c2c796868
https://github.com/spring-projects/spring-security/commit/7dbb8e777ece86
75f3333a1ef1cb4d6b9be80395
https://github.com/spring-projects/spring-security/commit/a7005bd74241ac
8e2e7b38ae31bc4b0f641ef973