跳转到帖子

Red Hat JBossEAP: Improper Handling of Case Sensitivity (CVE-2024-38829)

recommended_posts

发布于
  • Members

Red Hat JBossEAP: Improper Handling of Case Sensitivity (CVE-2024-38829)

Severity
3
CVSS
(AV:N/AC:H/Au:N/C:P/I:N/A:N)
Published
12/04/2024
Created
12/24/2024
Added
12/20/2024
Modified
12/20/2024

Description

A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from 2.4.0 through 2.4.3, from 3.0.0 through 3.0.9, from 3.1.0 through 3.1.7, from 3.2.0 through 3.2.7, AND all versions prior to 2.4.0. The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in unintended columns from being queried Related toCVE-2024-38820 https://spring.io/security/cve-2024-38820. A flaw was found in Spring LDAP. The usage of String.toLowerCase() and String.toUpperCase() has some locale dependent exceptions that could result in unintended columns being queried.

Solution(s)

  • red-hat-jboss-eap-upgrade-latest

References

  • https://attackerkb.com/topics/cve-2024-38829
  • CVE - 2024-38829
  • https://access.redhat.com/security/cve/CVE-2024-38829
  • https://bugzilla.redhat.com/show_bug.cgi?id=2330449
  • https://spring.io/security/cve-2024-38829
  • 查看数 699
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…