CVE-2019-11272

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
26/06/2019
Last modified:
12/09/2025

Description

Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of "null".

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:spring_security:*:*:*:*:*:*:*:* 4.2.13 (excluding)
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*