In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0479 | In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase. |
Github GHSA |
GHSA-6gf2-pvqw-37ph | Log entry injection in Spring Framework |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2024-08-03T18:30:23.916Z
Reserved: 2021-01-04T00:00:00
Link: CVE-2021-22060
No data.
Status : Modified
Published: 2022-01-10T14:10:16.680
Modified: 2024-11-21T05:49:31.040
Link: CVE-2021-22060
OpenCVE Enrichment
No data.
EUVD
Github GHSA