The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
{ "versions": [ { "introduced": "6.1.0" }, { "fixed": "6.1.14" } ] }
[ { "events": [ { "introduced": "5.3.0" }, { "fixed": "5.3.41" } ] }, { "events": [ { "introduced": "6.0.0" }, { "fixed": "6.0.25" } ] } ]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-38820.json"