← Back to CVE List

CVE-2024-38820

Published: 2024-10-18T06:15Z
Last Modified: 2024-11-29T12:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt