CVE Published: 22/06/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: vmware |
Vendor: n/a |
Product: Spring Data MongoDB Status : PUBLISHED
CVE-2022-22980 Description
A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.