« Volver al listado

CVE-2024-38820

Estado: ModificadaMedia (5.3)—

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-38820",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-38820",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-18T16:33:48.971617Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@vmware.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.1,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.6
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "VMware",
          "product": "Spring",
          "versions": [
            {
              "status": "affected",
              "version": "5.3.x",
              "lessThan": "5.3.41",
              "versionType": "Enterprise Support Only"
            },
            {
              "status": "affected",
              "version": "6.0.x",
              "lessThan": "6.0.25",
              "versionType": "Enterprise Support Only"
            },
            {
              "status": "affected",
              "version": "6.1.x",
              "lessThan": "6.1.14",
              "versionType": "OSS"
            }
          ],
          "packageName": "Spring Framework",
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-10-18T06:15:03.333",
  "references": [
    {
      "url": "https://spring.io/security/cve-2024-38820",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20241129-0003/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-178"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected."
    },
    {
      "lang": "es",
      "value": "La corrección de CVE-2022-22968 hizo que los patrones disallowedFields en DataBinder no distingan entre mayúsculas y minúsculas. Sin embargo, String.toLowerCase() tiene algunas excepciones dependientes de la configuración regional que podrían generar campos no protegidos como se esperaba."
    }
  ],
  "lastModified": "2026-06-17T07:41:06.497",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF21F5D2-C4C5-4F24-AC72-D035237FF88E",
              "versionEndExcluding": "5.3.41",
              "versionStartIncluding": "5.3.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39D2699C-C6AD-4D79-A35B-2D273FA1C97C",
              "versionEndExcluding": "6.0.25",
              "versionStartIncluding": "6.0.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34886C2E-A108-48D6-9536-D33EF3C90A0A",
              "versionEndExcluding": "6.1.14",
              "versionStartIncluding": "6.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}