CVE-2024-38820
EUVD-2024-293318.10.2024, 06:15
The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vmware | spring_framework | 5.3.0 ≤ 𝑥 < 5.3.41 |
| vmware | spring_framework | 6.0.0 ≤ 𝑥 < 6.0.25 |
| vmware | spring_framework | 6.1.0 ≤ 𝑥 < 6.1.14 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| vmware | spring | 5.3.0 ≤ 𝑥 < 5.3.41 | CNA |
| vmware | spring | 6.0.0 ≤ 𝑥 < 6.0.25 | CNA |
| vmware | spring | 6.1.0 ≤ 𝑥 < 6.1.14 | CNA |
Debian Releases
Common Weakness Enumeration