Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-22980 — [CVE-2022-22980] Spring Data MongoDB SpEL Expression Injection | Kitploit
Tools/GitHubGitHub/murataydemir/cve-2022-22980
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationLearning & EducationDatabase Security
GitHubmurataydemir/cve-2022-22980

CVE-2022-22980

[CVE-2022-22980] Spring Data MongoDB SpEL Expression Injection

View Repository
5194 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

[CVE-2022-22980] Spring Data MongoDB SpEL Expression Injection


MongoDB is a document-oriented NoSQL database with the scalable and flexible that used for high volume data storage. Instead of using tables and rows as in the traditional relational databases, MongoDB makes use of collections and documents. Documents consist of key-value pairs which are the basic unit of data in MongoDB.

Spring Data for MongoDB is part of the umbrella Spring Data project which aims to provide a familiar and consistent Spring-based programming model for new datastores while retaining store-specific features and capabilities. The Spring Data MongoDB project provides integration with the MongoDB document database. Key functional areas of Spring Data MongoDB are a POJO centric model for interacting with a MongoDB DBCollection and easily writing a Repository style data access layer.

On 20th June 2022, VMware released a security advisory on its official website that related to SpEL Expression Injection (leads to remote code execution) vulnerability affecting Spring Data MongoDB. You can find detailed information about the CVE-2022-22980 vulnerability in the down below.

Vulnerability
A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized. Alternatively, arrangements that expose repository query methods without involving additional application code (such as Spring Data REST) are vulnerable as well.

Specifically, an application is vulnerable when all of the following are true:

  • a repository query method is annotated with @Query or @Aggregation that make use of SpEL (Spring Expression Language) and use input parameter references (?0, ?1, …) within the SpEL expression
  • the annotated query or aggregation value/pipeline contains SpEL parts using the parameter placeholder syntax within the expression
  • the user supplied input is not sanitized by the application
  • Spring Data MongoDB 3.4.0, 3.3.0 to 3.3.4, and older versions

An application is not vulnerable if any of the following is true:

  • the annotated repository query or aggregation method does not contain expressions
  • the annotated repository query or aggregation method does not use the parameter placeholder syntax within the expression
  • the user supplied input is sanitized by the application
  • the repository is configured to use a QueryMethodEvaluationContextProvider that limits SpEL usage

Affected Versions
Spring Data MongoDB 3.4.0, 3.3.0 to 3.3.4, and older versions are affected by CVE-2022-22980 Spring Data MongoDB SpEL Expression Injection vulnerability.

Status
Spring Data MongoDB 3.4.1 and 3.3.5, which contain the fixes, have been released.

Mitigation and Suggested Workarounds
The preferred response is to update to Spring Data MongoDB 3.4.1 and 3.3.5 or greater. If you have done this, then no workarounds are necessary. However, some may be in a position where upgrading is impossible to do quickly. For that reason, Spring team have provided some workarounds below.

  • Using array syntax: if the application requires dynamic SpEL expressions that are controlled by user input, then rewrite query or aggregation declarations to use parameter references ([0] instead of ?0) within the expression
  • Implementing a custom repository method: Replacing the SpEL expression with a custom repository method implementation is a viable workaround to assemble your dynamic query within the application code. Refer to the reference documentation on repository customization for further details.
  • Sanitize parameters before calling the query method

Patch Analysis: GitHub Issue and Related Commits
GitHub issue for SpEL injection vulnerability can be accessible from github.com/spring-projects/spring-data-mongodb/issues/4089.
With the help of the two commit in below, related vulnerability has been fixed.

  • 7c5ac764b343d45e5d0abbaba4e82395b471b4c4
  • 5e241c6ea55939c9587fad5058a07d7b3f0ccbd3

With these commits spring-data-mongodb/src/main/java/org/springframework/data/mongodb/util/json/EvaluationContextExpressionEvaluator.java class has been added.

class EvaluationContextExpressionEvaluator implements SpELExpressionEvaluator {

	ValueProvider valueProvider;
	ExpressionParser expressionParser;
	Supplier<EvaluationContext> evaluationContext;

	public EvaluationContextExpressionEvaluator(ValueProvider valueProvider, ExpressionParser expressionParser,
			Supplier<EvaluationContext> evaluationContext) {

		this.valueProvider = valueProvider;
		this.expressionParser = expressionParser;
		this.evaluationContext = evaluationContext;
	}

	@Nullable
	@Override
	public <T> T evaluate(String expression) {
		return evaluateExpression(expression, Collections.emptyMap());
	}

	public EvaluationContext getEvaluationContext(String expressionString) {
		return evaluationContext != null ? evaluationContext.get() : new StandardEvaluationContext();
	}

	public SpelExpression getParsedExpression(String expressionString) {
		return (SpelExpression) (expressionParser != null ? expressionParser : new SpelExpressionParser())
				.parseExpression(expressionString);
	}

	public <T> T evaluateExpression(String expressionString, Map<String, Object> variables) {

		SpelExpression expression = getParsedExpression(expressionString);
		EvaluationContext ctx = getEvaluationContext(expressionString);
		variables.entrySet().forEach(entry -> ctx.setVariable(entry.getKey(), entry.getValue()));

		Object result = expression.getValue(ctx, Object.class);
		return (T) result;
	}
}

Screenshot 2022-06-28 102025

spring-projects/spring-data-mongodb/blob/main/spring-data-mongodb/src/main/java/org/springframework/data/mongodb/util/json/ParameterBindingContext.java class has also been modified as follow:

Screenshot 2022-06-28 105719

Download Tool