GHSA-4gc7-5j7h-4qph
Spring Framework DataBinder Case Sensitive Match Exception
Quick fix
GHSA-4gc7-5j7h-4qph — org.springframework:spring-context: upgrade to the fixed version with the command below.
# pom.xml: bump <version>6.1.14</version> for org.springframework:spring-contextDetails
The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
Are you affected?
Enter the version of the package you're using.
Affected packages
6.1.0Fixed in: 6.1.14# pom.xml: bump <version>6.1.14</version> for org.springframework:spring-context6.1.0Fixed in: 6.1.14# pom.xml: bump <version>6.1.14</version> for org.springframework:spring-web6.0.0No fixed version published yet for org.springframework:spring-web (maven). Pin to a known-safe version or switch to an alternative.
6.0.0No fixed version published yet for org.springframework:spring-context (maven). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for org.springframework:spring-context (maven). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for org.springframework:spring-web (maven). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-38820[ADVISORY]
- https://github.com/spring-projects/spring-framework/commit/23656aebc6c7d0f9faff1080981eb4d55eff296c[WEB]
- https://github.com/spring-projects/spring-framework[PACKAGE]
- https://github.com/spring-projects/spring-framework/commits/v6.2.0-RC2[WEB]
- https://security.netapp.com/advisory/ntap-20241129-0003[WEB]
- https://spring.io/security/cve-2024-38820[WEB]