spring-ldap-core is vulnerable to Exposure of Sensitive Information
60
Medium Risk
Affected versions of this package may inadvertently expose sensitive information due to Locale-dependent exceptions in the use of String.toLowerCase() and String.toUpperCase(). These exceptions can cause unintended columns to be queried, potentially leaking data that should remain protected.
You are affected if you are using a version which is within vulnerability ranges
spring-ldap-core is vulnerable to Exposure of Sensitive Information in versions 0.0.1 - 2.4.3, 3.0.0 - 3.0.9, 3.1.0 - 3.1.7 and 3.2.0 - 3.2.7.
Upgrade the org.springframework.ldap:spring-ldap-core library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant