CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.3. See the original NVD description below for full technical details.
CVE
CVE-2019-11272
Severity
HIGH
CVSS
7.3
EPSS
1.37%
Original NVD Description
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user has a null encoded password, a malicious user (or attacker) can authenticate using a password of "null".
Related CVEs
Other vulnerabilities affecting the same vendor(s)