Description
DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.
Remediation
References
http://support.springsource.com/security/CVE-2012-5055
Related Vulnerabilities
CVE-2017-15288 Vulnerability in maven package org.scala-lang:scala-compiler
CVE-2018-12542 Vulnerability in maven package io.vertx:vertx-web
CVE-2023-36477 Vulnerability in maven package org.xwiki.contrib:application-ckeditor-ui
CVE-2023-35155 Vulnerability in maven package org.xwiki.platform:xwiki-platform-sharepage-api