CVE-2024-38820
EUVD-2024-293318.10.2024, 06:15
The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vmware | spring_framework | 5.3.0 ≤ 𝑥 < 5.3.41 |
| vmware | spring_framework | 6.0.0 ≤ 𝑥 < 6.0.25 |
| vmware | spring_framework | 6.1.0 ≤ 𝑥 < 6.1.14 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration