cbcvebase.
CVE-2019-3797
published 2019-05-06

CVE-2019-3797: This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the predicates ‘startingWith’…

PriorityP427medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
1.09%
61.5th percentile
This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the predicates ‘startingWith’, ‘endingWith’ or ‘containing’ could return more results than anticipated when a maliciously crafted query parameter value is supplied. Also, LIKE expressions in manually defined queries could return unexpected results if the parameter values bound did not have escaped reserved characters properly.

Affected

6 ranges
VendorProductVersion rangeFixed in
pivotal_softwarespring_data_java_persistence_api1.11.0 – 1.11.19
pivotal_softwarespring_data_java_persistence_api2.0.0 – 2.0.13
pivotal_softwarespring_data_java_persistence_api2.1.0 – 2.1.5
springspring_boot>= 1.5 < v1.5.20.RELEASEv1.5.20.RELEASE
springspring_boot>= 2.0 < v2.0.9.RELEASEv2.0.9.RELEASE
springspring_boot>= 2.1 < v2.1.4.RELEASEv2.1.4.RELEASE

CVSS provenance

nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.