Expression Language Injection in Spring Data MongoDB - CVE-2022-22980
Published: June 21, 2022 / Updated: July 14, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to SpEL injection issue through annotated repository query methods. A remote attacker can execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
IBM Planning Analytics Workspace
Storage Copy Data Management
Storage Protect Plus Server
Autodesk Infraworks
How to mitigate CVE-2022-22980
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
IBM Planning Analytics Workspace - update to 2.0.82
Storage Copy Data Management - update to 2.2.23.0
Storage Protect Plus Server - update to 10.1.16.1
Links to Public Exploits and PoC-codes
- Exploit #8142 - Spring_cve-2022-22980 (spring data mongodb remote code execution | cve-2022-22980 poc) (July 14, 2022)
- Exploit #8069 - cve-2022-22980-exp (CVE-2022-22980 exp demo可作为扫描器靶场) (June 22, 2022)
- Exploit #8068 - cve-2022-22980 (CVE-2022-22980 exp && 靶场) (June 22, 2022)
- Exploit #8067 - Spring-Data-Mongodb-Demo (CVE-2022-22980环境) (June 22, 2022)
- Exploit #8063 - Spring-Data-Mongodb-Example (CVE-2022-22980环境) (June 22, 2022)
- Exploit #8060 - CVE-2022-22980 (Poc of CVE-2022-22980) (June 22, 2022)