CVE-2019-3802: Additional information exposure with Spring Data JPA example matcher
This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results than anticipated when a maliciously crafted example value is supplied.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3802?
CVE-2019-3802 is a vulnerability that affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14, and 1.11.20.
How does CVE-2019-3802 impact Spring Data JPA?
CVE-2019-3802 allows a maliciously crafted ExampleMatcher to return more results than expected.
What is the severity of CVE-2019-3802?
CVE-2019-3802 has a severity rating of medium with a CVSS score of 5.3.
How can I fix CVE-2019-3802?
To fix CVE-2019-3802, upgrade Spring Data JPA to version 2.1.7, 2.0.15, or 1.11.21.
Where can I find more information about CVE-2019-3802?
You can find more information about CVE-2019-3802 on the CVE website, NVD, Pivotal Security, Bugzilla, and Red Hat.