PT-2022-3045 · Spring · Spring Data Mongodb

Zewei Zhang

·

Published

2022-06-21

·

Updated

2022-06-30

·

CVE-2022-22980

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Spring Data MongoDB (affected versions not specified)
Description The issue is related to errors in processing SpEL expressions, which can be exploited by a remote attacker to execute arbitrary code by sending a specially crafted SpEL request. This can occur when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding, if the input is not sanitized.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03714
CVE-2022-22980
GHSA-W24X-87MR-4R23

Affected Products

Spring Data Mongodb