Echo: org.springframework:spring-context: security update to 6.1.20

low Tenable Cloud Security Plugin ID 461894

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields
patterns and for request parameter names. However, there are still cases where it is possible to bypass
the disallowedFields checks. Affected Spring Products and Versions Spring Framework: * 6.2.0 - 6.2.6 *
6.1.0 - 6.1.19 * 6.0.0 - 6.0.27 * 5.3.0 - 5.3.42 * Older, unsupported versions are also affected
Mitigation Users of affected versions should upgrade to the corresponding fixed version. Affected
version(s)Fix Version Availability 6.2.x 6.2.7 OSS6.1.x 6.1.20 OSS6.0.x 6.0.28 Commercial
https://enterprise.spring.io/ 5.3.x 5.3.43 Commercial https://enterprise.spring.io/ No further mitigation
steps are necessary. Generally, we recommend using a dedicated model object with properties only for data
binding, or using constructor binding since constructor arguments explicitly declare what to bind together
with turning off setter binding through the declarativeBinding flag. See the Model Design section in the
reference documentation. For setting binding, prefer the use of allowedFields (an explicit list) over
disallowedFields. Credit This issue was responsibly reported by the TERASOLUNA Framework Development Team
from NTT DATA Group Corporation. (CVE-2025-22233)

Solution

Update the org.springframework:spring-context library and its related packages to version 6.1.20 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-22233

Plugin Details

Severity: Low

ID: 461894

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Low

Base Score: 2.1

Temporal Score: 1.6

Vector: CVSS2#AV:N/AC:H/Au:S/C:N/I:P/A:N

CVSS Score Source: CVE-2025-22233

CVSS v3

Risk Factor: Low

Base Score: 3.1

Temporal Score: 2.7

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 5/16/2025

Reference Information

CVE: CVE-2025-22233