CVE-2024-38820

MEDIUM5.3EPSS 1.5%

Spring Framework DataBinder Case Sensitive Match Exception

發布日:2024/10/18修改日:2026/2/4
也稱為:GHSA-4gc7-5j7h-4qphCGA-9grp-6g38-66x6

描述

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

參考連結(7)