Description
DaoAuthenticationProvider in VMware SpringSource Spring Security before 2.0.8, 3.0.x before 3.0.8, and 3.1.x before 3.1.3 does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.
Remediation
References
http://support.springsource.com/security/CVE-2012-5055
Related Vulnerabilities
CVE-2011-2093 Vulnerability in maven package com.adobe.blazeds:flex-messaging-core
CVE-2021-21695 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2016-3721 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2018-7408 Vulnerability in maven package org.webjars.bower:npm