CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vmware 1Springsource Spring Security Apr 29, 2026 Dec 5, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and m...Show more |
1Vmware 1Springsource Spring Security Apr 29, 2026 Dec 5, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response split...Show more |
1Vmware 1Springsource Spring Security Apr 29, 2026 Dec 5, 2012 N/A· v4 N/A· v3 5.1 MEDIUM· v2 Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain priv...Show more |
3Acegisecurity IbmVmware3Acegi Security Springsource Spring SecurityWebsphere Application ServerApr 29, 2026 Oct 29, 2010 N/A· v4 N/A· v3 5.0 MEDIUM· v2 VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security...Show more |