Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3802

Опубликовано: 16 июл. 2019
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results than anticipated when a maliciously crafted example value is supplied.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1730316spring-data-api: potential information disclosure through maliciously crafted example value in ExampleMatcher

EPSS

Процентиль: 67%
0.01247
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 7 лет назад

This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results than anticipated when a maliciously crafted example value is supplied.

CVSS3: 5.3
github
около 7 лет назад

Improper Neutralization of Wildcards or Matching Symbols

EPSS

Процентиль: 67%
0.01247
Низкий

5.3 Medium

CVSS3

Уязвимость CVE-2019-3802