Description
A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.
Remediation
References
https://tanzu.vmware.com/security/cve-2022-22980
Related Vulnerabilities
CVE-2014-9634 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2018-1999038 Vulnerability in maven package org.jenkins-ci.plugins:publish-over-cifs
CVE-2020-28052 Vulnerability in maven package org.bouncycastle:bcprov-ext-jdk14
CVE-2023-32996 Vulnerability in maven package io.jenkins.plugins:miniorange-saml-sp
CVE-2021-32050 Vulnerability in maven package org.webjars.npm:mongodb