CVE-2022-22980
SpEL Injection in Spring Data MongoDB
Description
A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.
Base CVSS
9.8
EPSS Score
86.35%
Introduced Version
2.2.0.RELEASE
Fix Available
3.3.5,3.4.1
Available Patches
Package
CVEs Fixed
Lines of Code Changed