pivotalsoftware spring-security CVE-2020-5408 in Pivotal Software and VMware Products
Published on May 14, 2020

Dictionary attack with Spring Security queryable text encryptor

product logo product logo
Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious user with access to the data that has been encrypted using such an encryptor may be able to derive the unencrypted values using a dictionary attack.

NVD

Weakness Type

Not Using an Unpredictable IV with CBC Mode

Not using an unpredictable initialization Vector (IV) with Cipher Block Chaining (CBC) Mode causes algorithms to be susceptible to dictionary attacks when they are encrypted under the same key.


Products Associated with CVE-2020-5408

stack.watch emails you whenever new vulnerabilities are published in Pivotal Software Spring Security or VMware Spring Security. Just hit a watch button to start following.

 
 

Affected Versions

Spring by VMware Spring Security:

Exploit Probability

EPSS
0.47%
Percentile
64.19%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.