Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-38829

Опубликовано: 04 дек. 2024
Источник: nvd
CVSS3: 3.7
EPSS Низкий

Описание

A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from 2.4.0 through 2.4.3, from 3.0.0 through 3.0.9, from 3.1.0 through 3.1.7, from 3.2.0 through 3.2.7, AND all versions prior to 2.4.0.

The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in unintended columns from being queried Related to CVE-2024-38820 https://spring.io/security/cve-2024-38820

EPSS

Процентиль: 31%
0.00379
Низкий

3.7 Low

CVSS3

Дефекты

CWE-178

Связанные уязвимости

CVSS3: 3.7
ubuntu
почти 2 года назад

A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from 2.4.0 through 2.4.3, from 3.0.0 through 3.0.9, from 3.1.0 through 3.1.7, from 3.2.0 through 3.2.7, AND all versions prior to 2.4.0. The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in unintended columns from being queried Related to CVE-2024-38820 https://spring.io/security/cve-2024-38820

CVSS3: 3.7
redhat
почти 2 года назад

A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from 2.4.0 through 2.4.3, from 3.0.0 through 3.0.9, from 3.1.0 through 3.1.7, from 3.2.0 through 3.2.7, AND all versions prior to 2.4.0. The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in unintended columns from being queried Related to CVE-2024-38820 https://spring.io/security/cve-2024-38820

CVSS3: 3.7
debian
почти 2 года назад

A vulnerability in Spring LDAP allows data exposure for case sensitive ...

CVSS3: 3.7
github
почти 2 года назад

Spring LDAP data exposure vulnerability

CVSS3: 3.7
fstec
почти 2 года назад

Уязвимость функций String.toLowerCase() и String.toUpperCase() проекта для упрощения работы с LDAP (Lightweight Directory Access Protocol) Spring LDAP, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 31%
0.00379
Низкий

3.7 Low

CVSS3

Дефекты

CWE-178