{"id":"CVE-2019-3802","aliases":["GHSA-xggx-fx6w-v7ch"],"url":"https://o3.security/vulnerability/CVE-2019-3802","summary":"Improper Neutralization of Wildcards or Matching Symbols","details":"This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results than anticipated when a maliciously crafted example value is supplied.","published":"2019-06-03T14:29:00.340Z","modified":"2026-07-08T16:08:15.169476Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.springframework.data:spring-data-jpa","fixedVersion":"2.1.8"},{"ecosystem":"Maven","name":"org.springframework.data:spring-data-jpa","fixedVersion":"2.1.8"},{"ecosystem":"Maven","name":"org.springframework.data:spring-data-jpa","fixedVersion":"1.11.22"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://pivotal.io/security/cve-2019-3802"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T16:08:15.169476Z"}}