Related Vulnerabilities: CVE-2022-22980  

A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.

Description

The MITRE CVE dictionary describes this issue as:

A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.

Additional Information

  • Bugzilla 2102823: CVE-2022-22980 Spring Data MongoDB: SpEL in query methods allow code injection
  • CWE-20: Improper Input Validation
  • FAQ: Frequently asked questions about CVE-2022-22980