The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in authorization rules not working properly.
History

Tue, 03 Dec 2024 01:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 02 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 02 Dec 2024 14:45:00 +0000

Type Values Removed Values Added
Description The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in authorization rules not working properly.
Title Spring Security Authorization Bypass for Case Sensitive Comparisons
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published: 2024-12-02T14:32:12.471Z

Updated: 2024-12-02T15:27:27.060Z

Reserved: 2024-06-19T22:32:07.790Z

Link: CVE-2024-38827

cve-icon Vulnrichment

Updated: 2024-12-02T15:27:20.844Z

cve-icon NVD

Status : Received

Published: 2024-12-02T15:15:11.270

Modified: 2024-12-02T15:15:11.270

Link: CVE-2024-38827

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-12-02T14:32:12Z

Links: CVE-2024-38827 - Bugzilla