Vulnerability

CVE-2024-38827
CVSS Score 6.3 medium

CVSS Vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

CWE

CWE-639

[CVE-2024-38827] CWE-639: Authorization Bypass Through User-Controlled Key

Description

The usage of String.toLowerCase()�and String.toUpperCase()�has some Locale�dependent exceptions that could potentially result in authorization rules not working properly.