Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-22980

A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.863
EPSS Ranking 99.4%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 6.8
Products affected by CVE-2022-22980


Contact Us

Shodan ® - All rights reserved