Description
A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.
Remediation
References
https://tanzu.vmware.com/security/cve-2022-22980
Related Vulnerabilities
CVE-2022-43403 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2023-30522 Vulnerability in maven package org.jenkins-ci.plugins:fogbugz
CVE-2023-37895 Vulnerability in maven package org.apache.jackrabbit:jackrabbit-webapp
CVE-2015-1808 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-15842 Vulnerability in maven package com.liferay:com.liferay.portal.template.freemarker