CVE-2024-38820

ADVISORY - github

Summary

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

EPSS Score: 0.00631 (0.454)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Improper Handling of Case Sensitivity

ADVISORY - github

Improper Handling of Case Sensitivity

ADVISORY - gitlab

OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities

Improper Handling of Case Sensitivity

OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in