CVE Vulnerabilities

CVE-2024-38820

Published: Oct 18, 2024 | Modified: Nov 29, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

Affected Software

NameVendorStart VersionEnd Version
Spring_frameworkVmware5.3.0 (including)5.3.41 (excluding)
Spring_frameworkVmware6.0.0 (including)6.0.25 (excluding)
Spring_frameworkVmware6.1.0 (including)6.1.14 (excluding)
Libspring-javaUbuntufocal*
Libspring-javaUbuntuoracular*
Libspring-javaUbuntuplucky*
Libspring-javaUbuntutrusty/esm*

References