Vulnerabilities > Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-06-03 CVE-2022-26134 Expression Language Injection vulnerability in Atlassian Confluence Data Center and Confluence Server
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance.
network
low complexity
atlassian CWE-917
critical
9.8
2022-04-25 CVE-2022-26111 Expression Language Injection vulnerability in Canon Irisnext 9.8.28
The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents.
network
low complexity
canon CWE-917
8.8
2022-04-13 CVE-2022-24847 Expression Language Injection vulnerability in Osgeo Geoserver
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data.
network
low complexity
osgeo CWE-917
7.2
2022-04-13 CVE-2022-24818 Expression Language Injection vulnerability in Geotools
GeoTools is an open source Java library that provides tools for geospatial data.
network
low complexity
geotools CWE-917
7.2
2022-04-12 CVE-2021-31805 Expression Language Injection vulnerability in Apache Struts
The fix issued for CVE-2020-17530 was incomplete.
network
low complexity
apache CWE-917
critical
9.8
2022-04-01 CVE-2022-22963 Expression Language Injection vulnerability in multiple products
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
network
low complexity
vmware oracle CWE-917
critical
9.8
2022-03-03 CVE-2022-22947 Expression Language Injection vulnerability in multiple products
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.
network
low complexity
vmware oracle CWE-917
critical
10.0
2021-09-09 CVE-2021-32834 Expression Language Injection vulnerability in Eclipse Keti
Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC).
network
low complexity
eclipse CWE-917
critical
9.9
2021-08-30 CVE-2021-26084 Expression Language Injection vulnerability in Atlassian Confluence Data Center and Confluence Server
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance.
network
low complexity
atlassian CWE-917
critical
9.8
2021-07-31 CVE-2020-26565 Expression Language Injection vulnerability in Objectplanet Opinio
ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter.
network
low complexity
objectplanet CWE-917
7.5