Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use Locale.ROOT for locale neutral, case insensitive comparisons #33708

Closed
rstoyanchev opened this issue Oct 15, 2024 · 2 comments
Closed

Use Locale.ROOT for locale neutral, case insensitive comparisons #33708

rstoyanchev opened this issue Oct 15, 2024 · 2 comments
Assignees
Labels
in: core Issues in core modules (aop, beans, core, context, expression) in: web Issues in web modules (web, webmvc, webflux, websocket) type: enhancement A general enhancement
Milestone

Comments

@rstoyanchev
Copy link
Contributor

No description provided.

@rstoyanchev rstoyanchev added in: web Issues in web modules (web, webmvc, webflux, websocket) in: core Issues in core modules (aop, beans, core, context, expression) type: enhancement A general enhancement labels Oct 15, 2024
@rstoyanchev rstoyanchev added this to the 6.1.14 milestone Oct 15, 2024
@rstoyanchev rstoyanchev self-assigned this Oct 15, 2024
@jhoeller jhoeller self-assigned this Oct 16, 2024
@rstoyanchev rstoyanchev changed the title Use Locale.ROOT for locale neutral, lower-case comparisons Use Locale.ROOT for locale neutral, case insensitive comparisons Oct 16, 2024
bclozel added a commit that referenced this issue Oct 16, 2024
This commit adds a checkstyle rule that prevents the re-introduction of
such calls.

See gh-33708
@milosonator
Copy link

If I understand correctly, this issue related to CVE-2024-38820, and 11d4272 is the fix for this, can you confirm please?

Are there any known problematic comparisons for common locales such as en_US?

@bclozel
Copy link
Member

bclozel commented Oct 21, 2024

Sorry @milosonator but we don't comment publicly on CVE fixes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
in: core Issues in core modules (aop, beans, core, context, expression) in: web Issues in web modules (web, webmvc, webflux, websocket) type: enhancement A general enhancement
Projects
None yet
Development

No branches or pull requests

4 participants