CVE-2024-38829: Spring LDAP Spring LDAP sensitive data exposure for case-sensitive comparisons
Description
The usage of String.toLowerCase()
and String.toUpperCase()
has some Locale
dependent exceptions that could potentially result in unintended columns from being queried
Related to CVE-2024-38820
Affected Spring Products and Versions
Spring LDAP:
- 2.4.0 - 2.4.3
- 3.0.0 - 3.0.9
- 3.1.0 - 3.1.7
- 3.2.0 - 3.2.7
- Older, unsupported versions are also affected …