CVE-2024-38827: Spring Security Authorization Bypass for Case Sensitive Comparisons

4.8 CVSS

Description

The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in authorization rules not working properly.

Classification

CVE ID: CVE-2024-38827

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.8

Affected Products

Vendor: Spring by VMware Tanzu

Product: Spring Security

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://spring.io/security/cve-2024-38827

Timeline