CVE-2024-38827
Spring Security Authorization Bypass for Case Sensitive Comparisons
The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in authorization rules not working properly.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected products
Spring by VMware Tanzu · Spring SecurityWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →