The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
2024-10-18T06:15:03.333
2024-11-29T12:15:07.007
Modified
CVSSv3.1: 3.1 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | spring_framework | < 5.3.41 | Yes |
Application | vmware | spring_framework | < 6.0.25 | Yes |
Application | vmware | spring_framework | < 6.1.14 | Yes |