DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.
                
            References
                    | Link | Resource | 
|---|---|
| http://support.springsource.com/security/CVE-2012-5055 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
Configuration 2 (hide)
            
            
  | 
    
Configuration 3 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2012-12-05 17:55
Updated : 2012-12-28 05:00
NVD link : CVE-2012-5055
Mitre link : CVE-2012-5055
CVE.ORG link : CVE-2012-5055
JSON object : View
Products Affected
                vmware
- springsource_spring_security
 
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
