Description
In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0479 | In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase. |
Github GHSA |
GHSA-6gf2-pvqw-37ph | Log entry injection in Spring Framework |
References
History
No history.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2024-08-03T18:30:23.916Z
Reserved: 2021-01-04T00:00:00.000Z
Link: CVE-2021-22060
No data.
Status : Modified
Published: 2022-01-10T14:10:16.680
Modified: 2024-11-21T05:49:31.040
Link: CVE-2021-22060
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA