GHSA-6q3q-6v5j-h6vg
HIGHCVE-2024-49203The order by method enables injecting HQL queries. This may cause blind HQL injection, which could lead to leakage of sensitive information, and potentially also Denial Of Service. This vulnerability is present since the original querydsl repository(https://github.com/querydsl/querydsl) where it was assigned preliminary CVE identifier CVE-2024-49203.
- Affected
- >= 6.0.0.M1, < 6.10.1
- Fixed in
- 6.10.1
- Weakness
- CWE-89
- Published
- 2024-11-27
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereference