Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41697

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (STARTING, ENDING, or CONTAINING) in Query By Example (QBE). An attacker can supply wildcard characters to perform boolean-based blind data inference. Affected versions: Spring Data Relational/JDBC/R2DBC 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.4.0 through 2.4.19.

A flaw was found in Spring Data Relational. This vulnerability allows a remote attacker to perform boolean-based blind data inference by supplying wildcard characters in externally-controlled input when using StringMatcher in Query By Example (QBE). This can lead to the disclosure of sensitive information.

Отчет

A flaw was found in Spring Data Relational. The Query By Example implementation does not properly escape wildcard characters in StringMatcher bindings, allowing an attacker to perform boolean-based blind data inference. Exploitation requires the application to use QBE with StringMatcher (STARTING, ENDING, or CONTAINING) and pass externally-controlled input to the query.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform Expansion Packspring-data-relationalFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=2487397Spring Data Relational: Spring Data Relational: Information disclosure via improper input escaping in Query By Example

EPSS

Процентиль: 13%
0.00227
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 4.8
nvd
2 месяца назад

Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (STARTING, ENDING, or CONTAINING) in Query By Example (QBE). An attacker can supply wildcard characters to perform boolean-based blind data inference. Affected versions: Spring Data Relational/JDBC/R2DBC 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.4.0 through 2.4.19.

CVSS3: 4.8
github
2 месяца назад

Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (STARTING, ENDING, or CONTAINING) in Query By Example (QBE). An attacker can supply wildcard characters to perform boolean-based blind data inference. Affected versions: Spring Data Relational/JDBC/R2DBC 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.4.0 through 2.4.19.

EPSS

Процентиль: 13%
0.00227
Низкий

3.7 Low

CVSS3