CVE-2024-38827: Spring By VMware Tanzu Spring Security

Medium severity, CVSS 4.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in authorization rules not working properly.

Affected products

Published 2024-12-02. Last modified 2026-06-17.