CVE-2024-38827

ADVISORY - github

Summary

The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in authorization rules not working properly.

EPSS Score: 0.00377 (0.294)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Authorization Bypass Through User-Controlled Key

ADVISORY - github

Authorization Bypass Through User-Controlled Key

ADVISORY - gitlab

OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities

Authorization Bypass Through User-Controlled Key

OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities

ADVISORY - redhat

Authorization Bypass Through User-Controlled Key


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in