Vulnerability Description
This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results than anticipated when a maliciously crafted example value is supplied.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Spring Data Java Persistance Api | >= 1.11.0, <= 1.11.21 |
Related Weaknesses (CWE)
References
- https://pivotal.io/security/cve-2019-3802Vendor Advisory
- https://pivotal.io/security/cve-2019-3802Vendor Advisory
FAQ
What is CVE-2019-3802?
CVE-2019-3802 is a vulnerability with a CVSS score of 5.3 (MEDIUM). This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatche...
How severe is CVE-2019-3802?
CVE-2019-3802 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-3802?
Check the references section above for vendor advisories and patch information. Affected products include: Pivotal Software Spring Data Java Persistance Api.