Lucene search

K
osvGoogleOSV:GHSA-W24X-87MR-4R23
HistoryJun 24, 2022 - 12:00 a.m.

SpEL Injection in Spring Data MongoDB

2022-06-2400:00:30
Google
osv.dev
97

0.004 Low

EPSS

Percentile

75.2%

A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.