spring-data-commons is vulnerable to Uncontrolled Resource Consumption
75
High Risk
Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings are passed to MappingContext property path resolution.
You are affected if you are using a version that falls within the vulnerable range and requires attacker-controlled property path input, exposure to untrusted callers, and recursive/deeply nested domain graphs or many unique invalid paths.
spring-data-commons is vulnerable to Uncontrolled Resource Consumption in versions 3.4.0 - 3.4.14, 3.5.0 - 3.5.11 and 4.0.0 - 4.0.5.
Upgrade the org.springframework.data:spring-data-commons library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant