Description
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g5mm-vmx4-3rg7 | Improper handling of case sensitivity in Spring Framework |
References
History
No history.
Subscriptions
Netapp
Subscribe
Active Iq Unified Manager
Subscribe
Cloud Secure Agent
Subscribe
Metrocluster Tiebreaker
Subscribe
Snap Creator Framework
Subscribe
Snapmanager
Subscribe
Oracle
Subscribe
Mysql Enterprise Monitor
Subscribe
Redhat
Subscribe
Amq Broker
Subscribe
Jboss Fuse
Subscribe
Vmware
Subscribe
Spring Framework
Subscribe
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2024-08-03T03:28:42.847Z
Reserved: 2022-01-10T00:00:00.000Z
Link: CVE-2022-22968
No data.
Status : Modified
Published: 2022-04-14T21:15:08.643
Modified: 2024-11-21T06:47:42.537
Link: CVE-2022-22968
OpenCVE Enrichment
No data.
Github GHSA