VDB
Sign up
MEDIUM5.3

GHSA-4gc7-5j7h-4qph

Spring Framework DataBinder Case Sensitive Match Exception

Quick fix

GHSA-4gc7-5j7h-4qph — org.springframework:spring-context: upgrade to the fixed version with the command below.

# pom.xml: bump <version>6.1.14</version> for org.springframework:spring-context

Details

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.springframework:spring-context
Introduced in: 6.1.0Fixed in: 6.1.14
Fix# pom.xml: bump <version>6.1.14</version> for org.springframework:spring-context
Maven/org.springframework:spring-web
Introduced in: 6.1.0Fixed in: 6.1.14
Fix# pom.xml: bump <version>6.1.14</version> for org.springframework:spring-web
Maven/org.springframework:spring-web
Introduced in: 6.0.0

No fixed version published yet for org.springframework:spring-web (maven). Pin to a known-safe version or switch to an alternative.

Maven/org.springframework:spring-context
Introduced in: 6.0.0

No fixed version published yet for org.springframework:spring-context (maven). Pin to a known-safe version or switch to an alternative.

Maven/org.springframework:spring-context
Introduced in: 0

No fixed version published yet for org.springframework:spring-context (maven). Pin to a known-safe version or switch to an alternative.

Maven/org.springframework:spring-web
Introduced in: 0

No fixed version published yet for org.springframework:spring-web (maven). Pin to a known-safe version or switch to an alternative.

References