Description
This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results than anticipated when a maliciously crafted example value is supplied.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0572 | This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results than anticipated when a maliciously crafted example value is supplied. |
Github GHSA |
GHSA-xggx-fx6w-v7ch | Improper Neutralization of Wildcards or Matching Symbols |
References
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-17T00:22:02.219Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3802
No data.
Status : Modified
Published: 2019-06-03T14:29:00.340
Modified: 2024-11-21T04:42:34.247
Link: CVE-2019-3802
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA