CVE-2019-3802 PUBLISHED CVSS 3.5 LOW

Reported by dell · Published June 3, 2019

This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results than anticipated when a maliciously crafted example value is supplied.

Risk Scores

CVSS v3.0
3.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
SpringSpring Data JPA2.1, 1.11
Mavenorg.springframework.data:spring-data-jpa1.11.0, 1.11.0
SpringSpring Data JPA2.1, 1.11, 2.1

Timeline

References

Open in Interactive Console →