Lucene search

K
osvGoogleOSV:CVE-2022-22980
HistoryJun 23, 2022 - 5:15 p.m.

CVE-2022-22980

2022-06-2317:15:12
Google
osv.dev
7

6.9 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

75.2%

A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.

6.9 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

75.2%