Skip to content

fix(deps): bump spring-ldap to 2.4.4 - #55

Closed
kathrynalpert wants to merge 1 commit into
developfrom
fix/cve-2024-38829-spring-ldap
Closed

fix(deps): bump spring-ldap to 2.4.4#55
kathrynalpert wants to merge 1 commit into
developfrom
fix/cve-2024-38829-spring-ldap

Conversation

@kathrynalpert

@kathrynalpert kathrynalpert commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

No description provided.

CVE-2024-38829 (Medium) affects Spring LDAP 2.4.3 and earlier: the same
class of locale-dependent String.toLowerCase()/toUpperCase() defect as
CVE-2024-38827, here causing unintended data queries. 2.4.4 is the
vendor's fix for the 2.4.x branch and is published on Maven Central, so
unlike the rest of this line it needs no framework migration.

This does not clear CVE-2026-41720 (authentication bypass with an empty
password), which the vendor lists as affecting 2.4.4 and earlier; its fix
is 2.4.5 and is not published publicly. That is tracked separately.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@kathrynalpert

Copy link
Copy Markdown
Contributor Author

Superseded by #57, which combines this with the other two follow-ups from the same dependency pass for easier review. Same commit, cherry-picked.

@kathrynalpert
kathrynalpert deleted the fix/cve-2024-38829-spring-ldap branch September 4, 2026 15:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant