Generated remediation guidance and an executive summary. No account required.
Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious user with access to the data that has been encrypted using such an encryptor may be able to derive the unencrypted values using a dictionary attack.
Use CWE-329, Pivotal Software vendor hub and Spring Security product page to widen CVE-2020-5408 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-22112, CVE-2020-5407 and CVE-2018-1258 for nearby disclosures in the same product family. Additional editorial context is available in Cybersecurity Weekly Roundup: April 27, 2026 — Critical Zero-Days and Framework Failures.