imPC@ndo IT

Tracker / CVE-2024-38820

CVE-2024-38820

Low 3.1

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

Affected products and versions

vmware spring_framework · 5.3.0 → 5.3.41
vmware spring_framework · 6.0.0 → 6.0.25
vmware spring_framework · 6.1.0 → 6.1.14

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References