CVE-2024-38820 | VMware Spring up to 5.3.40/6.0.24/6.1.13 DataBinder String.toLowerCase access control (Nessus ID 209652 / WID-SEC-2026-0559)
A vulnerability labeled as critical has been found in VMware Spring up to 5.3.40/6.0.24/6.1.13. This issue affects the function String.toLowerCase of the component DataBinder. The manipulation results in improper access controls.
This vulnerability was named CVE-2024-38820. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.