CVE Vulnerabilities

CVE-2024-38820

Published: Oct 18, 2024 | Modified: Nov 29, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

Affected Software

Name Vendor Start Version End Version
Spring_framework Vmware 5.3.0 (including) 5.3.41 (excluding)
Spring_framework Vmware 6.0.0 (including) 6.0.25 (excluding)
Spring_framework Vmware 6.1.0 (including) 6.1.14 (excluding)
Libspring-java Ubuntu trusty/esm *

References