nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-3802 CVE-2019-3802
MEDIUM
Additional information exposure with Spring Data JPA example matcher
Record summary
CVE-2019-3802 has a selected CVSS score of 5.3 (medium).
Description
This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results than anticipated when a maliciously crafted example value is supplied.
Description source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Spring Data JPABrowse Spring / Spring Data JPA | CVE List | 2.1 to < 2.1.8.RELEASE | affected |
| 1.11 to < 1.11.22.RELEASE | affected | ||
org.springframework.data:spring-data-jpaBrowse Maven / org.springframework.data:spring-data-jpa | GitHub Advisory | 2.1.0 to < 2.1.8 · Fixed in 2.1.8 | affected |
| 2.0.0 to < 2.1.8 · Fixed in 2.1.8 | affected | ||
| Before 1.11.22 · Fixed in 1.11.22 | affected |
References
2pivotal.ioConfirmation
https://pivotal.io/security/cve-2019-3802