Executive brief
Spring Data Commons contains a property binder vulnerability due to improper neutralization of special elements. An unauthenticated remote attacker can use specially crafted request parameters against Spring Data REST backed HTTP resources or projection-based request payload binding to achieve remote code execution.
Affected products
- VMware Tanzu Spring Data Commons prior to 1.13.11, 2.0 to 2.0.6, and older unsupported versions
- VMware Tanzu Spring Data REST up to 2.5.10, 2.6.0 to 2.6.10, 3.0.0 to 3.0.5
- Apache Ignite 1.0.0 to 2.5.0
Timeline
- 2022-03-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2022-03-25: disclosed