Intel

AIKIDO-2024-10467

spring-ldap-core is vulnerable to Exposure of Sensitive Information

Exposure of Sensitive InformationCVE-2024-38829 Published Nov 22, 2024

60

Medium Risk

This Affects:

javaspring-ldap-core
0.0.1 - 2.4.3
Fixed in 2.4.4
3.0.0 - 3.0.9
Fixed in 3.0.10
3.1.0 - 3.1.7
Fixed in 3.1.8
3.2.0 - 3.2.7
Fixed in 3.2.8
Are you affected? Scan for Free

TL;DR

Affected versions of this package may inadvertently expose sensitive information due to Locale-dependent exceptions in the use of String.toLowerCase() and String.toUpperCase(). These exceptions can cause unintended columns to be queried, potentially leaking data that should remain protected.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

spring-ldap-core is vulnerable to Exposure of Sensitive Information in versions 0.0.1 - 2.4.3, 3.0.0 - 3.0.9, 3.1.0 - 3.1.7 and 3.2.0 - 3.2.7.

How to fix this

Upgrade the org.springframework.ldap:spring-ldap-core library to a patch version.