CVE-2020-5428
Description
In applications using Spring Cloud Task 2.2.4.RELEASE and below, may be vulnerable to SQL injection when exercising certain lookup queries in the TaskExplorer.
CWE
- CWE-89 — CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Affected
- Spring by VMware / Spring Cloud Task — v=2.2 <2.2.5 [affected]
CVSS
- 3.0 score=5.1 severity=MEDIUM
CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L
References
- https://tanzu.vmware.com/security/cve-2020-5428 x_refsource_CONFIRM
Source
cvelistV5-main/cves/2020/5xxx/CVE-2020-5428.json