CVE-2024-49203

Querydsl 5.1.0-OpenFeign Querydsl 6.8 - SQL Injection

Title source: llm
STIX 2.1

Description

Querydsl 5.1.0 and OpenFeign Querydsl 6.8 allows SQL/HQL injection in orderBy in JPAQuery. NOTE: this is disputed by a Querydsl community member because the product is not intended to defend against a developer who uses untrusted input directly in query construction.

Scores

EPSS 0.0021
EPSS Percentile 43.4%

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

Status published
Products (4)
com.querydsl/querydsl-apt 0Maven
com.querydsl/querydsl-jpa 0Maven
io.github.openfeign.querydsl/querydsl-apt 6.0.0.M1 - 6.10.1Maven
io.github.openfeign.querydsl/querydsl-jpa 6.0.0.M1 - 6.10.1Maven
Published Nov 20, 2024
Tracked Since Feb 18, 2026