Publish GHSA-mqvr-2rp8-j7h4

This commit is contained in:
advisory-database[bot]
2024-12-10 16:30:27 +00:00
parent 89426e9f73
commit 30f0eb6b2e
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mqvr-2rp8-j7h4",
"modified": "2024-12-04T22:33:48Z",
"modified": "2024-12-10T16:29:00Z",
"published": "2024-12-04T21:30:52Z",
"aliases": [
"CVE-2024-38829"
],
"summary": "Spring LDAP data exposure vulnerability",
"details": "A vulnerability in VMware Tanzu Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from 2.4.0 through 2.4.3, from 3.0.0 through 3.0.9, from 3.1.0 through 3.1.7, from 3.2.0 through 3.2.7, AND all versions prior to 2.4.0.\n\nThe usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in unintended columns from being queried\nRelated to CVE-2024-38820 https://spring.io/security/cve-2024-38820",
"details": "A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from 2.4.0 through 2.4.3, from 3.0.0 through 3.0.9, from 3.1.0 through 3.1.7, from 3.2.0 through 3.2.7, AND all versions prior to 2.4.0.\n\nThe usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in unintended columns from being queried\nRelated to CVE-2024-38820 https://spring.io/security/cve-2024-38820",
"severity": [
{
"type": "CVSS_V3",