LOW3.7
GHSA-mqvr-2rp8-j7h4
Spring LDAP data exposure vulnerability
Quick fix
GHSA-mqvr-2rp8-j7h4 — org.springframework.ldap:spring-ldap-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.2.8</version> for org.springframework.ldap:spring-ldap-coreDetails
A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from 2.4.0 through 2.4.3, from 3.0.0 through 3.0.9, from 3.1.0 through 3.1.7, from 3.2.0 through 3.2.7, AND all versions prior to 2.4.0.
The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in unintended columns from being queried Related to CVE-2024-38820 https://spring.io/security/cve-2024-38820
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.springframework.ldap:spring-ldap-core
Introduced in:
3.0.0Fixed in: 3.2.8Fix
# pom.xml: bump <version>3.2.8</version> for org.springframework.ldap:spring-ldap-coreMaven/org.springframework.ldap:spring-ldap-core
Introduced in:
0Fixed in: 2.4.4Fix
# pom.xml: bump <version>2.4.4</version> for org.springframework.ldap:spring-ldap-core