Intel

AIKIDO-2024-10471

spring-security-ldap is vulnerable to Authorization Bypass

Authorization BypassCVE-2024-38827 Published Nov 22, 2024

60

Medium Risk

This Affects:

javaspring-security-ldap
0.0.1 - 5.7.13
Fixed in 5.7.14
5.8.0 - 5.8.15
Fixed in 5.8.16
6.0.0 - 6.0.13
Fixed in 6.0.14
6.1.0 - 6.1.11
Fixed in 6.1.12
6.2.0 - 6.2.7
Fixed in 6.2.8
6.3.0 - 6.3.4
Fixed in 6.3.5
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to an authorization bypass caused by Locale-dependent exceptions in the handling of String.toLowerCase() and String.toUpperCase(). This flaw can lead to unauthorized access by failing to properly normalize strings for comparison.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

spring-security-ldap is vulnerable to Authorization Bypass in versions 0.0.1 - 5.7.13, 5.8.0 - 5.8.15, 6.0.0 - 6.0.13, 6.1.0 - 6.1.11, 6.2.0 - 6.2.7 and 6.3.0 - 6.3.4.

How to fix this

Upgrade the org.springframework.security:spring-security-ldap library to a patch version.