Published: 23/06/2022 Updated: 23/06/2022

Vulnerability Summary

A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.

Vulnerability Trend

Github Repositories

CVE-2022-22980 Poc of CVE-2022-22980

spring-data-mongodb-cve-2022-22980-exp

[CVE-2022-22980] Spring Data MongoDB SpEL Expression Injection