3.4.5
13 years ago
16 days ago
Known vulnerabilities in the org.springframework.data:spring-data-jpa package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.springframework.data:spring-data-jpa is a package that is used to implement JPA based repositories. Affected versions of this package are vulnerable to Information Exposure. Using How to fix Information Exposure? Upgrade | [,1.11.22.RELEASE)[2.0.0.RELEASE,2.1.8.RELEASE) |
org.springframework.data:spring-data-jpa is a package that is used to implement JPA based repositories. Affected versions of this package are vulnerable to Information Exposure due to the usage of certain derived queries. A maliciously crafted query parameter value supplied with queries using How to fix Information Exposure? Upgrade | [2.0.0.RELEASE,2.0.14.RELEASE)[2.1.0.RELEASE,2.1.6.RELEASE)[,1.11.20.RELEASE) |
org.springframework.data:spring-data-jpa is a package that is used to implement JPA based repositories. Affected versions of this package are vulnerable to SQL Injection. Attackers to execute arbitrary JPQL commands via a sort instance with a function call, when used with a repository that defines a String query using the @Query annotation. How to fix SQL Injection? Upgrade | [,1.9.6.RELEASE)[1.10.0.RELEASE,1.10.4.RELEASE) |