Description
A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.
Remediation
References
https://tanzu.vmware.com/security/cve-2022-22980
Related Vulnerabilities
CVE-2020-11987 Vulnerability in maven package org.apache.xmlgraphics:batik-svgbrowser
CVE-2022-35949 Vulnerability in npm package undici
CVE-2020-10204 Vulnerability in maven package org.sonatype.nexus:nexus-core
CVE-2023-2976 Vulnerability in maven package com.google.guava:guava
CVE-2022-22932 Vulnerability in maven package org.apache.karaf:apache-karaf