{"id":"GHSA-w559-623p-vfg8","summary":"MyBatis PageHelper vulnerable to time-blind SQL injection via orderBy parameter","details":"MyBatis PageHelper versions 3.5.x through 5.3.x were discovered to contain a time-blind SQL injection vulnerability via the orderBy parameter.","aliases":["CVE-2022-28111"],"modified":"2024-02-17T05:33:57.079803Z","published":"2022-05-05T00:00:25Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-10-20T18:39:47Z","nvd_published_at":"2022-05-04T13:15:00Z","cwe_ids":["CWE-89"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-28111"},{"type":"WEB","url":"https://github.com/pagehelper/Mybatis-PageHelper/issues/674"},{"type":"WEB","url":"https://github.com/pagehelper/Mybatis-PageHelper/commit/554a524af2d2b30d09505516adc412468a84d8fa"},{"type":"PACKAGE","url":"https://github.com/pagehelper/Mybatis-PageHelper"},{"type":"WEB","url":"https://github.com/pagehelper/Mybatis-PageHelper.git"},{"type":"WEB","url":"https://github.com/yangfar/CVE/blob/main/CVE-2022-42227.md"},{"type":"WEB","url":"https://pagehelper.github.io"},{"type":"WEB","url":"https://www.cnblogs.com/secload/articles/16061420.html"}],"affected":[{"package":{"name":"com.github.pagehelper:pagehelper","ecosystem":"Maven","purl":"pkg:maven/com.github.pagehelper/pagehelper"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.5.0"},{"fixed":"5.3.1"}]}],"versions":["3.5.0","3.5.1","3.6.0","3.6.1","3.6.2","3.6.3","3.6.4","3.7.0","3.7.1","3.7.2","3.7.3","3.7.4","3.7.5","3.7.6","4.0.0","4.0.1","4.0.2","4.0.3","4.1.0","4.1.1","4.1.2","4.1.3","4.1.4","4.1.5","4.1.6","4.2.0","4.2.1","5.0.0","5.0.0-beta","5.0.0-rc","5.0.1","5.0.2","5.0.2-beta","5.0.3","5.0.3-beta","5.0.4","5.1.0","5.1.0-beta","5.1.0-beta2","5.1.1","5.1.10","5.1.11","5.1.2","5.1.2-beta","5.1.3","5.1.4","5.1.5","5.1.6","5.1.7","5.1.8","5.1.9","5.2.0","5.2.1","5.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-w559-623p-vfg8/GHSA-w559-623p-vfg8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}