spring-data-mongodb is vulnerable to SpEL Expression Injection
81
High Risk
Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs during parameter binding when a user-defined repository query method is annotated with @Query and utilizes a capture-all placeholder.
You are affected if you are using a version that falls within the vulnerable range.
spring-data-mongodb is vulnerable to SpEL Expression Injection in versions 0.0.0 - 3.4.19, 4.0.0 - 4.3.16, 4.4.0 - 4.4.14, 4.5.0 - 4.5.11 and 5.0.0 - 5.0.5.
Upgrade the org.springframework.data:spring-data-mongodb library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant