Thanks to visit codestin.com
Credit goes to github.com

Skip to content

[GHSA-4wp7-92pw-q264] CVE-2024-38820 ensured Locale-independent, lowercase... #5683

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Conversation

ryanmurf
Copy link

Updates

  • Affected products
  • References
  • Source code location
  • Summary

Comments
spring-projects/spring-framework#34801

@Copilot Copilot AI review requested due to automatic review settings May 31, 2025 21:16
@github-actions github-actions bot changed the base branch from main to ryanmurf/advisory-improvement-5683 May 31, 2025 21:17
Copy link

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the advisory metadata for GHSA-4wp7-92pw-q264 by adjusting timestamps, enriching the affected versions list, and adding new references.

  • Updated modified timestamp and added a more descriptive summary
  • Populated the affected section with detailed Maven ranges for multiple Spring Framework versions
  • Added PACKAGE and additional WEB references to the advisory
Comments suppressed due to low confidence (1)

advisories/unreviewed/2025/05/GHSA-4wp7-92pw-q264/GHSA-4wp7-92pw-q264.json:10

  • The details field still references CVE-2024-38820, but the advisory ID and context have moved to CVE-2025-22233—please update the CVE identifier here for consistency.
"details": "CVE-2024-38820 ensured Locale-independent, lowercase conversion..."

@advisory-database advisory-database bot merged commit 06f87b6 into ryanmurf/advisory-improvement-5683 Jun 2, 2025
4 checks passed
@advisory-database
Copy link
Contributor

Hi @ryanmurf! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the ryanmurf-GHSA-4wp7-92pw-q264 branch June 2, 2025 16:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant