PT-2026-35227 · Baomidou · Dynamic-Datasource
Winegee
·
Published
2026-04-26
·
Updated
2026-04-27
·
CVE-2026-7045
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
baomidou dynamic-datasource version 2.5.0
Description
An injection issue exists in the
doDetermineDatasource() function within the DsSpelExpressionProcessor class. This flaw, located in the StandardEvaluationContext/SpelExpressionParser component, allows for remote manipulation.Recommendations
Apply patch 273fcedaee984c08197c0890f14190b86ab7e0b8 to version 2.5.0.
As a temporary workaround, restrict access to the
doDetermineDatasource() function to minimize the risk of exploitation.Fix
Improper Neutralization
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dynamic-Datasource