Is org.springframework.data:spring-data-mongodbsafe?
3 known vulnerabilities, worst severity CRITICAL.
cvss
9.0
how bad it is if exploited, out of 10
epss
17.8%
chance of exploitation in the next 30 days
xyz score
4.6
CyberXYZ composite, out of 10
fig. 01 — GHSA-w24x-87mr-4r23, the advisory selected below
// advisories
GHSA-w24x-87mr-4r23
CRITICALCVE-2022-22980
A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.