CVE-2024-38820
18.10.2024, 06:15
The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBindercase insensitive. However, String.toLowerCase()has some Locale dependent exceptions that could potentially result in fields not protected as expected.Enginsight
Vendor | Product | Version |
---|---|---|
vmware | spring_framework | 5.3.0 ≤ 𝑥 < 5.3.41 |
vmware | spring_framework | 6.0.0 ≤ 𝑥 < 6.0.25 |
vmware | spring_framework | 6.1.0 ≤ 𝑥 < 6.1.14 |
𝑥
= Vulnerable software versions

Debian Releases
Common Weakness Enumeration