Boletines de Vulnerabilidades

DSA-4046 libspring-ldap-java - security update


Información sobre el sistema

   
Software afectado Debian

Descripción

Tobias Schneider discovered that libspring-ldap-java, a Java libraryfor Spring-based applications using the Lightweight Directory AccessProtocol, would under some circumstances allow authentication with acorrect username but an arbitrary password.

More info:

https://www.debian.org/security/2017/dsa-4046

Identificadores estándar

Propiedad Valor
CVE CVE-2017-8028 and DSA-4046.

Histórico de versiones

Versión Comentario Data
1.0 Advisory issued 2017-11-23
Ministerio de Defensa
CNI
CCN
CCN-CERT