Description
A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.
Remediation
References
https://tanzu.vmware.com/security/cve-2022-22980
Related Vulnerabilities
CVE-2016-4567 Vulnerability in maven package org.webjars.bower:mediaelement
CVE-2021-21169 Vulnerability in npm package electron
CVE-2017-1000356 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2018-1306 Vulnerability in maven package org.apache.portals.pluto:portletv3annotateddemo
CVE-2016-6637 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server