Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted sources.
The application is vulnerable if all of the following are true:
Sort parameters from untrusted input and uses them without prior sanitization as input for native SQL repository methods.@NativeQuery or @Query(nativeQuery=true).Sort or Pageable parameter.On affected databases inference of data characteristics through deterministic sorting is possible.
Spring Data JPA:
| Fix version | Availability |
|---|---|
| 4.1.1 | OSS |
| 4.0.7 | OSS |
| 3.5.14 | Enterprise Support Only |
| 3.4.16 | Enterprise Support Only |
No further mitigation steps are necessary.
The issue was identified and responsibly reported by SharlongWen.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy