Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xggx-fx6w-v7ch

Опубликовано: 04 июн. 2019
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Improper Neutralization of Wildcards or Matching Symbols

This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results than anticipated when a maliciously crafted example value is supplied.

Пакеты

Наименование

org.springframework.data:spring-data-jpa

maven
Затронутые версииВерсия исправления

>= 2.1.0, < 2.1.8

2.1.8

Наименование

org.springframework.data:spring-data-jpa

maven
Затронутые версииВерсия исправления

>= 2.0.0, <= 2.0.14

2.1.8

Наименование

org.springframework.data:spring-data-jpa

maven
Затронутые версииВерсия исправления

< 1.11.22

1.11.22

EPSS

Процентиль: 47%
0.00243
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-155
CWE-200

Связанные уязвимости

CVSS3: 5.3
redhat
больше 6 лет назад

This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results than anticipated when a maliciously crafted example value is supplied.

CVSS3: 5.3
nvd
больше 6 лет назад

This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results than anticipated when a maliciously crafted example value is supplied.

EPSS

Процентиль: 47%
0.00243
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-155
CWE-200