B3NCLOUD ARTICLE INTELLIGENCE

ARTICLEVIEW

Zurück zu News

[Medium] CVE-2026-41697 – Spring Data Relational does not properly escape binding values of externally-con...

Medium CVE-2026-41697 Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (STARTING, ENDING, or CONTAINING) in Query By Example (QBE). An attacker can supply wildcard characters to perform boolean-based blind data inference. ...

Original-Artikel öffnen Zurück zur Übersicht