CVE-2025-22233: Spring Framework DataBinder Case Sensitive Match Exception (2nd update)
Description
CVE-2024-38820 ensured Locale-independent,
lowercase conversion for both the configured disallowedFields patterns and for request parameter names.
However, there are still cases where it is possible to bypass the disallowedFields checks.