.. _vulnerabilityManagement_securityAdvisory_2024_CVE-2024-38820: CVE-2024-38820 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Data: 2024-10-29 Severity: Medium CVSS Score: 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) Riferimenti: - `https://nvd.nist.gov/vuln/detail/CVE-2024-38820 `_ - `https://ossindex.sonatype.org/vulnerability/CVE-2024-38820 `_ - `https://spring.io/security/cve-2024-38820 `_ Libreria: org.springframework:\* < 5.3.41 **Descrizione** The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected. **GovWay** Versione affette: <= 3.3.15.p1 Risoluzione: 3.3.15.p2