Description
A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.
Remediation
References
https://tanzu.vmware.com/security/cve-2022-22980
Related Vulnerabilities
CVE-2023-32070 Vulnerability in maven package org.xwiki.rendering:xwiki-rendering-macro-html
CVE-2020-8141 Vulnerability in maven package org.webjars.npm:dot
CVE-2023-29523 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2023-0868 Vulnerability in maven package org.opennms:opennms-webapp
CVE-2023-32315 Vulnerability in maven package org.igniterealtime.openfire:xmppserver