CVE-2024-38820: VMware Spring Framework
Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.
The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
Affected products
- VMware Spring Framework: from 5.3.0, before 5.3.41 (fixed in 5.3.41); from 6.0.0, before 6.0.25 (fixed in 6.0.25); from 6.1.0, before 6.1.14 (fixed in 6.1.14)
Published 2024-10-18. Last modified 2026-06-17.