Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreThe fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
Spring Framework:
| Fix version | Availability |
|---|---|
| 6.1.14 | OSS |
| 6.0.25 | Enterprise Support Only |
| 5.3.41 | Enterprise Support Only |
No further mitigation steps are necessary.
The vulnerability was reported responsibly by Marek Parfianowicz, Principal Engineer at Atlassian.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy