Loading...
Loading...
DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.
December 5, 2012
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2012-5055
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.