CVE-2019-3802: Pivotal Software Spring Data Java Persistance API
Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.
This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results than anticipated when a maliciously crafted example value is supplied.
Affected products
- Pivotal Software Spring Data Java Persistance API: from 1.11.0, up to and including 1.11.21; from 2.0.0, up to and including 2.0.14; from 2.1.0, up to and including 2.1.7
Published 2019-06-03. Last modified 2026-06-17.