-
Notifications
You must be signed in to change notification settings - Fork 0
Description
Checkmarx (SCA): Vulnerable Package
Vulnerability: Read More about CVE-2022-22968
Checkmarx Project: igorlombacx/astlab2
Repository URL: https://github.com/igorlombacx/astlab2
Branch: main
Severity: MEDIUM
State: TO_VERIFY
Status: RECURRENT
Scan ID: 8caf1d69-ab69-4064-888d-abb555c4ebdc
In Spring Framework versions before 5.2.2.RELEASE, and 5.3.0 through 5.3.18, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.
Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: NONE
Availability impact: NONE
Remediation Upgrade Recommendation: 4.1.0.RC1