OSV-2023-872

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/spring-data-mongodb/OSV-2023-872.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2023-872
Published
2023-09-18T14:00:10.451327Z
Modified
2023-09-18T14:00:10.451623Z
Summary
Security exception in org.springframework.expression.spel.ast.OpPlus.getValueInternal
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=62457

Crash type: Security exception
Crash state:
org.springframework.expression.spel.ast.OpPlus.getValueInternal
org.springframework.util.ConcurrentReferenceHashMap$Segment.restructureIfNecessa
org.springframework.util.ConcurrentReferenceHashMap.purgeUnreferencedEntries
References

Affected packages

OSS-Fuzz / spring-data-mongodb

Package

Name
spring-data-mongodb
Purl
pkg:generic/spring-data-mongodb

Affected ranges

Type
GIT
Repo
https://github.com/spring-projects/spring-data-mongodb
Events

Affected versions

4.*

4.2.0-M3

Ecosystem specific

{
    "severity": "LOW"
}

Database specific

{
    "introduced_range": "8844b3031c89065cc0b546f1ccb2a74d7ec2f980:cd80c8441fb216dafa2f58128e3deb4987fa409b"
}