Описание
The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-apps/bionic | needs-triage | |
| esm-apps/focal | needs-triage | |
| esm-apps/jammy | needs-triage | |
| esm-apps/noble | needs-triage | |
| esm-apps/xenial | needs-triage | |
| esm-infra-legacy/trusty | needs-triage | |
| focal | ignored | end of standard support, was needs-triage |
| jammy | needs-triage | |
| noble | needs-triage |
Показывать по
10
3.1 Low
CVSS3
Связанные уязвимости
CVSS3: 3.1
nvd
около 1 года назад
The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
CVSS3: 3.1
debian
около 1 года назад
The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...
CVSS3: 5.3
github
около 1 года назад
Spring Framework DataBinder Case Sensitive Match Exception
3.1 Low
CVSS3