Description
In applications using Spring Cloud Task 2.2.4.RELEASE and below, may be vulnerable to SQL injection when exercising certain lookup queries in the TaskExplorer.
Remediation
References
https://tanzu.vmware.com/security/cve-2020-5428
Related Vulnerabilities
CVE-2021-31408 Vulnerability in maven package com.vaadin:flow-client
CVE-2016-3094 Vulnerability in maven package org.apache.qpid:qpid-broker-core
CVE-2020-5207 Vulnerability in maven package io.ktor:ktor-server-cio
CVE-2019-9737 Vulnerability in npm package editor.md
CVE-2018-5968 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind