GHSA-878w-7gxp-mc63

Suggest an improvement
Source
https://github.com/advisories/GHSA-878w-7gxp-mc63
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-878w-7gxp-mc63/GHSA-878w-7gxp-mc63.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-878w-7gxp-mc63
Aliases
Published
2022-02-09T22:16:53Z
Modified
2023-11-08T04:03:55.894980Z
Severity
  • 6.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L CVSS Calculator
Summary
SQL Injection in Spring Cloud Task
Details

In applications using Spring Cloud Task 2.2.4.RELEASE and below, may be vulnerable to SQL injection when exercising certain lookup queries in the TaskExplorer.

Database specific
{
    "nvd_published_at": "2021-01-27T18:15:00Z",
    "github_reviewed_at": "2021-04-05T23:12:48Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-89"
    ]
}
References

Affected packages

Maven / org.springframework.cloud:spring-cloud-task-dependencies

Package

Name
org.springframework.cloud:spring-cloud-task-dependencies
View open source insights on deps.dev
Purl
pkg:maven/org.springframework.cloud/spring-cloud-task-dependencies

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.5

Affected versions

1.*

1.0.0.RELEASE
1.0.1.RELEASE
1.0.2.RELEASE
1.0.3.RELEASE
1.1.0.RELEASE
1.1.1.RELEASE
1.1.2.RELEASE
1.2.0.RELEASE
1.2.1.RELEASE
1.2.2.RELEASE
1.2.3.RELEASE
1.2.4.RELEASE
1.3.0.RELEASE
1.3.1.RELEASE

2.*

2.0.0.RELEASE
2.0.1.RELEASE
2.0.2.RELEASE
2.1.0.RELEASE
2.1.1.RELEASE
2.1.2.RELEASE
2.1.3.RELEASE
2.1.4.RELEASE
2.2.0.RELEASE
2.2.1.RELEASE
2.2.2.RELEASE
2.2.3.RELEASE
2.2.4.RELEASE