spring-projects/spring-data-jpa

spring-projects/spring-data-jpa

Releases388
Frequency2 weeks 7 hours
Last Release
Stars3.26K
Simplifies the development of creating a JPA-based data access layer.

CVE History

CVEPublishedCVSS v3CVSS v2
6.8 MEDIUM

SQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a repository that defines a String query using the @Query annotation, allows attackers to execute arbitrary JPQL commands via a sort instance with a function call.