VDB

DEBIAN-CVE-2024-38820

DEBIAN-CVE-2024-38820 PUBLISHED CVSS 5.300000190734863 MEDIUM

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

Risk Scores

CVSS v3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected Products

VendorProductVersions
Debian:13libspring-java0, 4.3.30-4, 4.3.30-3
Debian:14libspring-java0, 4.3.30-3, 4.3.30-4
Debian:11libspring-java4.3.30-3, 4.3.30-4, 4.3.30-1
Debian:12libspring-java0, 4.3.30-4, 4.3.30-2

Timeline

  • Oct 18, 2024 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›