Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.
An attacker who could reach the LDAP listener port could authenticate using the well-known administrative bind DN, and then read or modify entries in the in-memory directory.
Preconditions:
UnboundIdContainer — configured directly or through Spring Boot auto-configuration (spring.ldap.embedded.* properties).Spring Security:
| Fix version | Availability |
|---|---|
| 7.1.1 | OSS |
| 7.1.0.1 | Enterprise Support Only |
| 7.0.7 | OSS |
| 7.0.6.1 | Enterprise Support Only |
| 6.5.12 | Enterprise Support Only |
| 6.4.19 | Enterprise Support Only |
| 5.8.28 | Enterprise Support Only |
| 5.7.26 | Enterprise Support Only |
No further mitigation steps are necessary.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy