Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreThe fix for CVE-2022-22968 made disallowedFields
patterns in DataBinder
case insensitive. However, String.toLowerCase()
has some Locale dependent exceptions that could potentially result in fields not protected as expected.
Spring Framework:
Users of affected versions should upgrade to the corresponding fixed version.
Affected version(s) | Fix version | Availability |
---|---|---|
5.3.x | 5.3.41 | Commercial |
6.0.x | 6.0.25 | Commercial |
6.1.x | 6.1.14 | OSS |
No other mitigation steps are necessary.
The vulnerability was reported responsibly by Marek Parfianowicz, Principal Engineer at Atlassian.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy