CVE-2024-38820: VMware Spring Framework

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

Affected products

  • VMware Spring Framework: from 5.3.0, before 5.3.41 (fixed in 5.3.41); from 6.0.0, before 6.0.25 (fixed in 6.0.25); from 6.1.0, before 6.1.14 (fixed in 6.1.14)

Published 2024-10-18. Last modified 2026-06-17.