Improper authorization control for web services In org.springframework:spring-jdbc
Description
Spring Framework has Authorization Bypass for Case Sensitive Comparisons The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in authorization rules not working properly.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 6.1.14 | ||
maven | 6.1.14 | ||
maven | 6.1.14 | ||
maven | 6.1.14 | ||
maven | 5.7.14, 5.8.16, 6.0.14, 6.1.12, 6.2.8, 6.3.5 | ||
maven | 6.1.14 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6.