GHSA-v33x-prhc-gph5
GitHub Security Advisory
Insufficiently Protected Credentials and Improper Authentication in Spring Security
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of ?null?.
Affected Packages
Maven
org.springframework.security:spring-security-core
Affected versions:
0
(fixed in 4.2.13)
Maven
org.springframework.security:spring-security-cas
Affected versions:
0
(fixed in 4.2.13.RELEASE)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: September 19, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.