This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results than anticipated when a maliciously crafted example value is supplied.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Spring_data_java_persistance_api | Pivotal_software | 1.11.0 (including) | 1.11.21 (including) |
Spring_data_java_persistance_api | Pivotal_software | 2.0.0 (including) | 2.0.14 (including) |
Spring_data_java_persistance_api | Pivotal_software | 2.1.0 (including) | 2.1.7 (including) |
Red Hat Fuse 7.6.0 | RedHat | spring-data-jpa | * |