Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6q3q-6v5j-h6vg | Querydsl vulnerable to HQL injection through orderBy |
Fri, 21 Feb 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Thu, 13 Feb 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Querydsl 5.1.0 and OpenFeign Querydsl 6.8 allows SQL/HQL injection in orderBy in JPAQuery. | Querydsl 5.1.0 and OpenFeign Querydsl 6.8 allows SQL/HQL injection in orderBy in JPAQuery. NOTE: this is disputed by a Querydsl community member because the product is not intended to defend against a developer who uses untrusted input directly in query construction. |
| References |
|
Thu, 19 Dec 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 03 Dec 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openfeign Querydsl
Openfeign Querydsl openfeign Querydsl Querydsl Querydsl querydsl |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:openfeign_querydsl:openfeign_querydsl:*:*:*:*:*:*:*:* cpe:2.3:a:querydsl:querydsl:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Openfeign Querydsl
Openfeign Querydsl openfeign Querydsl Querydsl Querydsl querydsl |
|
| Metrics |
cvssV3_1
|
Thu, 21 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Querydsl 5.1.0 allows SQL/HQL injection in orderBy in JPAQuery. | Querydsl 5.1.0 and OpenFeign Querydsl 6.8 allows SQL/HQL injection in orderBy in JPAQuery. |
| References |
|
Wed, 20 Nov 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Querydsl 5.1.0 allows SQL/HQL injection in orderBy in JPAQuery. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-21T16:52:31.005Z
Reserved: 2024-10-14T00:00:00.000Z
Link: CVE-2024-49203
Updated: 2024-12-03T15:49:25.606Z
Status : Deferred
Published: 2024-11-20T21:15:08.090
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-49203
No data.
OpenCVE Enrichment
No data.
No weakness.
Github GHSA