Record summary

CVE-2019-3802 has a selected CVSS score of 5.3 (medium).

Description

This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results than anticipated when a maliciously crafted example value is supplied.

Description source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List2.1 to < 2.1.8.RELEASEaffected
1.11 to < 1.11.22.RELEASEaffected

org.springframework.data:spring-data-jpa

Browse Maven / org.springframework.data:spring-data-jpa
GitHub Advisory2.1.0 to < 2.1.8 · Fixed in 2.1.8affected
2.0.0 to < 2.1.8 · Fixed in 2.1.8affected
Before 1.11.22 · Fixed in 1.11.22affected

References

2