SQL injection - Code In org.springframework.ai:spring-ai-mariadb-store
Description
SQL Injection in Spring AI MariaDBFilterExpressionConverter A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands.
The vulnerability exists due to missing input sanitization.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 1.1.3, 1.0.4 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.