CVE-2012-5055
Publication date 5 December 2012
Last updated 24 July 2024
Ubuntu priority
DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.
Status
Package | Ubuntu Release | Status |
---|---|---|
libspring-security-2.0-java | ||
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |