Описание
MyBatis-Plus vulnerable to SQL injection via TenantPlugin
MyBatis-Plus below 3.5.3.1 is vulnerable to SQL injection via the tenant ID value. This may allow remote attackers to execute arbitrary SQL commands.
Пакеты
Наименование
com.baomidou:mybatis-plus
maven
Затронутые версииВерсия исправления
< 3.5.3.1
3.5.3.1
Связанные уязвимости
CVSS3: 9.8
nvd
почти 3 года назад
A SQL injection vulnerability in Mybatis plus below 3.5.3.1 allows remote attackers to execute arbitrary SQL commands via the tenant ID valuer. NOTE: the vendor's position is that this can only occur in a misconfigured application; the documentation discusses how to develop applications that avoid SQL injection.