Description
In applications using Spring Cloud Task 2.2.4.RELEASE and below, may be vulnerable to SQL injection when exercising certain lookup queries in the TaskExplorer.
Remediation
References
https://tanzu.vmware.com/security/cve-2020-5428
Related Vulnerabilities
CVE-2021-21306 Vulnerability in npm package marked
CVE-2022-25918 Vulnerability in npm package shescape
CVE-2015-5170 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-login
CVE-2019-19771 Vulnerability in npm package bitcionjs
CVE-2019-10907 Vulnerability in maven package org.airsonic.player:airsonic-main