Authorization Rules May Not Work Properly Due to Locale-Dependent Exceptions in Java
CVE-2024-38827
4.8MEDIUM
What is CVE-2024-38827?
The usage of String.toLowerCase()Ā and String.toUpperCase()Ā has some LocaleĀ dependent exceptions that could potentially result in authorization rules not working properly.
Affected Version(s)
Spring Security 5.7.0 - 5.7.13, 5.8.0 - 5.8.15, 6.0.0 - 6.0.13, 6.1.0 - 6.1.11, 6.2.0 - 6.2.7, 6.3.0 - 6.3.4, Older unsupported versions are also affected
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved