CVE-2024-38827: Spring Security Authorization Bypass for Case Sensitive Comparisons
Description
The usage of String.toLowerCase()
and String.toUpperCase()
has some Locale
dependent exceptions that could potentially result in authorization rules not working properly.
Related to CVE-2024-38820
Affected Spring Products and Versions
Spring…