Home
HIGH: 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NDefault status
unaffected
2.4.0 (custom) before 2.4.5
affected
3.2.0 (custom) before 3.2.18
affected
3.3.0 (custom) before 3.3.8
affected
4.0.0 (custom) before 4.0.4
affected
Description
Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username is paired with an empty or null password. Affected versions: Spring LDAP 2.4.0 through 2.4.4; 3.2.0 through 3.2.17; 3.3.0 through 3.3.7; 4.0.0 through 4.0.3.
Problem types
CWE-287: Improper Authentication
Product status
2.4.0 (custom) before 2.4.5
3.2.0 (custom) before 3.2.18
3.3.0 (custom) before 3.3.8
4.0.0 (custom) before 4.0.4
References
spring.io/security/cve-2026-41720