Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreThe fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
Spring Framework:
Users of affected versions should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 5.3.x | 5.3.41 | Commercial |
| 6.0.x | 6.0.25 | Commercial |
| 6.1.x | 6.1.14 | OSS |
No other mitigation steps are necessary.
The vulnerability was reported responsibly by Marek Parfianowicz, Principal Engineer at Atlassian.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy