CVE-2019-3797
published 2019-05-06CVE-2019-3797: This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the predicates ‘startingWith’…
PriorityP427medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
1.09%
61.5th percentile
This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the predicates ‘startingWith’, ‘endingWith’ or ‘containing’ could return more results than anticipated when a maliciously crafted query parameter value is supplied. Also, LIKE expressions in manually defined queries could return unexpected results if the parameter values bound did not have escaped reserved characters properly.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| pivotal_software | spring_data_java_persistence_api | 1.11.0 – 1.11.19 | — |
| pivotal_software | spring_data_java_persistence_api | 2.0.0 – 2.0.13 | — |
| pivotal_software | spring_data_java_persistence_api | 2.1.0 – 2.1.5 | — |
| spring | spring_boot | >= 1.5 < v1.5.20.RELEASE | v1.5.20.RELEASE |
| spring | spring_boot | >= 2.0 < v2.0.9.RELEASE | v2.0.9.RELEASE |
| spring | spring_boot | >= 2.1 < v2.1.4.RELEASE | v2.1.4.RELEASE |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Exposure of Sensitive Information to an Unauthorized Actor and SQL Injection in Spring Data JPA
osv·2019-05-14
CVE-2019-3797 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor and SQL Injection in Spring Data JPA
Exposure of Sensitive Information to an Unauthorized Actor and SQL Injection in Spring Data JPA
This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the predicates ?startingWith?, ?endingWith? or ?containing? could return more results than anticipated when a maliciously crafted query parameter value is supplied. Also, LIKE expressions in manually defined queries could return unexpected results if the parameter values bound did not have escaped reserved characters properly.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor and SQL Injection in Spring Data JPA
ghsa·2019-05-14
CVE-2019-3797 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor and SQL Injection in Spring Data JPA
Exposure of Sensitive Information to an Unauthorized Actor and SQL Injection in Spring Data JPA
This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the predicates ?startingWith?, ?endingWith? or ?containing? could return more results than anticipated when a maliciously crafted query parameter value is supplied. Also, LIKE expressions in manually defined queries could return unexpected results if the parameter values bound did not have escaped reserved characters properly.
Red Hat
spring-data-jpa: Additional information exposure with Spring Data JPA derived queries
vendor_redhat·2019-04-08·CVSS 3.5
CVE-2019-3797 [LOW] CWE-200 spring-data-jpa: Additional information exposure with Spring Data JPA derived queries
spring-data-jpa: Additional information exposure with Spring Data JPA derived queries
This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the predicates ‘startingWith’, ‘endingWith’ or ‘containing’ could return more results than anticipated when a maliciously crafted query parameter value is supplied. Also, LIKE expressions in manually defined queries could return unexpected results if the parameter values bound did not have escaped reserved characters properly.
No detection rules found.
2019-05-06
Published