The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Spring_framework | Vmware | 5.3.0 (including) | 5.3.41 (excluding) |
Spring_framework | Vmware | 6.0.0 (including) | 6.0.25 (excluding) |
Spring_framework | Vmware | 6.1.0 (including) | 6.1.14 (excluding) |
Libspring-java | Ubuntu | trusty/esm | * |