spring-security-ldap is vulnerable to Use of Hard-coded Credentials
94
Critical Risk
spring-security-ldap embedded UnboundID LDAP server registers a well-known administrative bind DN and listens on all network interfaces. Anyone who can reach the LDAP port can bind as that admin and read or modify the in-memory directory. This applies when UnboundIdContainer is used directly or via spring.ldap.embedded.*. The patch binds locally by default and no longer exposes a well-known admin credential on all interfaces.
You are affected if you are using a version that falls within the vulnerable range and UnboundIdContainer is used with an LDAP listener that is reachable from the attacker.
spring-security-ldap is vulnerable to Use of Hard-coded Credentials in versions 5.7.0 - 7.0.6 and 7.1.0 - 7.1.0.
Upgrade the org.springframework.security:spring-security-ldap library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant