VDB
Sign up
LOW3.7

GHSA-mqvr-2rp8-j7h4

Spring LDAP data exposure vulnerability

Quick fix

GHSA-mqvr-2rp8-j7h4 — org.springframework.ldap:spring-ldap-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.2.8</version> for org.springframework.ldap:spring-ldap-core

Details

A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from 2.4.0 through 2.4.3, from 3.0.0 through 3.0.9, from 3.1.0 through 3.1.7, from 3.2.0 through 3.2.7, AND all versions prior to 2.4.0.

The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in unintended columns from being queried Related to CVE-2024-38820 https://spring.io/security/cve-2024-38820

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.springframework.ldap:spring-ldap-core
Introduced in: 3.0.0Fixed in: 3.2.8
Fix# pom.xml: bump <version>3.2.8</version> for org.springframework.ldap:spring-ldap-core
Maven/org.springframework.ldap:spring-ldap-core
Introduced in: 0Fixed in: 2.4.4
Fix# pom.xml: bump <version>2.4.4</version> for org.springframework.ldap:spring-ldap-core

References