In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade org.springframework.security:spring-security-ldap
to version 4.2.9.RELEASE, 5.0.9.RELEASE, 5.1.1.RELEASE or higher.
org.springframework.security:spring-security-ldap is a package that provides a comprehensive programming and configuration model for modern Java-based enterprise applications - on any kind of deployment platform.
Affected versions of this package are vulnerable to Authentication Bypass via the LdapUserDetailsManager
and the changePassword
methods.