spring-websocket is vulnerable to Improper Handling of Case Sensitivity
23
Low Risk
Affected versions of the package are vulnerable to improper handling of case sensitivity. The use of String.toLowerCase() introduces locale-dependent exceptions that can cause fields to be improperly protected, potentially allowing attackers to bypass security checks based on case variations that are not handled consistently across different locales.
You are affected if you are using a version that falls within the vulnerable range.
spring-websocket is vulnerable to Improper Handling of Case Sensitivity in versions 0.0.1 - 5.3.40, 6.0.0 - 6.0.24 and 6.1.0 - 6.1.13.
Upgrade the org.springframework:spring-websocket library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant