The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
| Software | From | Fixed in |
|---|---|---|
| vmware / spring_framework | 6.1.0 | 6.1.14 |
| vmware / spring_framework | 6.0.0 | 6.0.25 |
| vmware / spring_framework | 5.3.0 | 5.3.41 |