spring-data-keyvalue is vulnerable to SpEL Injection
64
Medium Risk
A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator.
You are affected if you are using a version that falls within the vulnerable range and if SpelPropertyComparator is used with untrusted input for sorting.
spring-data-keyvalue is vulnerable to SpEL Injection in versions 0.0.1 - 2.7.19, 3.0.0 - 3.3.16, 3.4.0 - 3.4.14, 3.5.0 - 3.5.11 and 4.0.0 - 4.0.5.
Upgrade the org.springframework.data:spring-data-keyvalue library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant