- Description
- Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segment used as the map key is embedded directly into a SpEL expression without sanitization or validation. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5.
- Source
- security@vmware.com
- NVD status
- Analyzed
- Products
- spring_data_rest
CVSS 3.1
- Type
- Secondary
- Base score
- 8.1
- Impact score
- 5.2
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity
- HIGH
- security@vmware.com
- CWE-917
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vmware:spring_data_rest:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D5AB0CD7-F756-4FCA-A328-B0F19CBDABD6",
"versionEndExcluding": "3.7.20",
"versionStartIncluding": "3.7.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:vmware:spring_data_rest:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3FA3D040-BCC5-4C66-A0AF-5383AC89048E",
"versionEndExcluding": "4.3.17",
"versionStartIncluding": "4.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:vmware:spring_data_rest:*:*:*:*:*:*:*:*",
"matchCriteriaId": "DEEF0B3D-C5D9-496A-B300-86876DE9F3B7",
"versionEndExcluding": "4.4.15",
"versionStartIncluding": "4.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:vmware:spring_data_rest:*:*:*:*:*:*:*:*",
"matchCriteriaId": "40757E5D-97AF-4680-A7F6-2EB1FD09D39E",
"versionEndExcluding": "4.5.11.1",
"versionStartIncluding": "4.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:vmware:spring_data_rest:*:*:*:*:*:*:*:*",
"matchCriteriaId": "42C8C99B-7F57-4CEE-859A-C6A005C23EFB",
"versionEndExcluding": "5.0.5.1",
"versionStartIncluding": "5.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]