Authorization Rules May Not Work Properly Due to Locale-Dependent Exceptions in Java
CVE-2024-38827
4.8MEDIUM
What is CVE-2024-38827?
The usage of String.toLowerCase()Ā and String.toUpperCase()Ā has some LocaleĀ dependent exceptions that could potentially result in authorization rules not working properly.
Affected Version(s)
Spring Security 5.7.0 - 5.7.13, 5.8.0 - 5.8.15, 6.0.0 - 6.0.13, 6.1.0 - 6.1.11, 6.2.0 - 6.2.7, 6.3.0 - 6.3.4, Older unsupported versions are also affected