Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-38827

Опубликовано: 02 дек. 2024
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in authorization rules not working properly.

A flaw was found in the Spring Security framework. The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in authorization rules not working properly. In some circumstances, this may lead to an authorization bypass.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2spring-security-coreNot affected
OpenShift Developer Tools and Servicesspring-security-coreAffected
Red Hat build of Apache Camel for Spring Boot 4spring-security-coreNot affected
Red Hat build of Apache Camel - HawtIO 4spring-security-coreAffected
Red Hat Build of Keycloakspring-security-coreNot affected
Red Hat Data Grid 8spring-security-coreWill not fix
Red Hat Fuse 7spring-security-coreOut of support scope
Red Hat Integration Camel K 1spring-security-coreNot affected
Red Hat JBoss Data Grid 7spring-security-coreNot affected
Red Hat JBoss Enterprise Application Platform 7spring-security-coreNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2329971spring-security: authorization bypass for case sensitive comparisons

EPSS

Процентиль: 32%
0.00385
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
nvd
почти 2 года назад

The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in authorization rules not working properly.

CVSS3: 4.8
debian
почти 2 года назад

The usage of String.toLowerCase()and String.toUpperCase()has some Loca ...

CVSS3: 4.8
github
почти 2 года назад

Spring Framework has Authorization Bypass for Case Sensitive Comparisons

CVSS3: 4.8
fstec
почти 2 года назад

Уязвимость функций String.toLowerCase() и String.toUpperCase() Java-фреймворка для обеспечения безопасности промышленных приложений Spring Security, позволяющая нарушителю обойти процесс авторизации

EPSS

Процентиль: 32%
0.00385
Низкий

4.8 Medium

CVSS3