The vendor explicitly identifies these products as affected by this CVE.
- springframework.src as a component of Logging Subsystem for Red Hat OpenShift
- springframework as a component of Red Hat Decision Manager 7
- springframework as a component of Red Hat Integration Camel K 1
- springframework as a component of Red Hat Integration Camel Quarkus 1
- springframework as a component of Red Hat Integration Data Virtualisation Operator
- springframework as a component of Red Hat JBoss Data Grid 7
- springframework as a component of Red Hat JBoss Data Virtualization 6
- springframework as a component of Red Hat JBoss Enterprise Application Platform 6
- springframework as a component of Red Hat JBoss Fuse 6
- springframework as a component of Red Hat JBoss Fuse Service Works 6
- springframework as a component of Red Hat Process Automation 7
- Summary
- In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.
- Remediation
- Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. The References section of this erratum contains a download link (you must log in to download the update).
