Back

HIGH

PlaintextPasswordEncoder authenticates encoded passwords that are null

Published Jun 26, 2019

Description

Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of "null".

Affected products

Remediation

Red Hat statement

Red Hat OpenStack Platform's OpenDaylight versions 9 and 10 contain the vulnerable code. However, these OpenDaylight versions were released as technical preview with limited support and will therefore not be updated. Other OpenDaylight versions do not contain the vulnerable library.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner pivotal
Published Jun 26, 2019
Updated Sep 16, 2024
Reserved Apr 18, 2019
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 11, 2019
GHSA-V33X-PRHC-GPH5