DirectorySecurity Advisories
Sign In
Security Advisories

CGA-rwg8-jxvr-5wxf

Published

Last updated

https://images.chainguard.dev/security/CGA-rwg8-jxvr-5wxf
Package

jenkins-2.479

Latest Update
Pending upstream fix
Aliases
  • CVE-2024-38827
  • GHSA-q3v6-hm2v-pw99

Severity

4.8

Medium

CVSS V3

Summary

Spring Framework has Authorization Bypass for Case Sensitive Comparisons

Description

The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially result in authorization rules not working properly.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images