ID:8069 - Exploit for Expression Language Injection in Spring Data MongoDB - CVE-2022-22980

 
Main Vulnerability Database Exploits ID:8069 - Exploit for Expression Language Injection in Spring Data MongoDB - CVE-2022-22980

ID:8069 - Exploit for Expression Language Injection in Spring Data MongoDB - CVE-2022-22980

Published: June 22, 2022


Vulnerability identifier: #VU64524
Vulnerability risk: High
CVE-ID: CVE-2022-22980
CWE-ID: CWE-917
Exploitation vector: Remote access
Vulnerable software:
Spring Data MongoDB

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to SpEL injection issue through annotated repository query methods. A remote attacker can execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.