Spring Security's embedded UnboundID LDAP server ( UnboundIdContainer ) unconditionally registers an administrative credential and binds its listener to all available network interfaces.
An attacker who could reach the LDAP listener port could authenticate using the well-known administrative bind DN, and then read or modify entries in the in-memory directory.
No further mitigation steps are necessary.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy
Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.
Check out all the upcoming events in the Spring community.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
