CVE-2020-16165: SQL Injection
(updated )
The DAO/DTO implementation in SpringBlade through allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list
ascs
and desc
parameters.
References
Detect and mitigate CVE-2020-16165 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →